CVE-2026-35388
Published Apr 2, 2026
·Updated
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
Affected Software
2 affected componentsFixes available
Microsoft azl3 openssh 9.8p1-5
OpenBSD OpenSSH<10.3
Event History
Apr 2, 2026
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software
Apr 4, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
Severity
Frequently Asked Questions
1
What is the severity of CVE-2026-35388?
CVE-2026-35388 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2026-35388?
To fix CVE-2026-35388, you should upgrade to OpenSSH version 10.3 or higher.
3
What products are affected by CVE-2026-35388?
CVE-2026-35388 affects OpenSSH versions prior to 10.3 in proxy-mode multiplexing sessions.
4
What are the implications of CVE-2026-35388?
CVE-2026-35388 can lead to potential security risks due to the omission of connection multiplexing confirmation.
5
Is there a workaround for CVE-2026-35388?
There are no known workarounds for CVE-2026-35388 other than upgrading to the patched version of OpenSSH.