CVE-2026-59995: Medium severity OpenSSH OpenSSH vulnerability
Last updated 13 July 2026
Other sources
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.8p1-9 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.4p1-1 - Upgrade
Upgrade
OpenSSH sftpto a version that resolves this vulnerability.Fixed in 10.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59995?
CVE-2026-59995 has a medium severity rating of 4.2.
How do I fix CVE-2026-59995?
To fix CVE-2026-59995, upgrade OpenSSH to version 10.4 or later.
What are the potential risks associated with CVE-2026-59995?
CVE-2026-59995 may allow an attacker to manipulate the location of downloaded files, leading to potential unauthorized access or data exposure.
Which versions of OpenSSH are affected by CVE-2026-59995?
OpenSSH versions before 10.4 are affected by CVE-2026-59995.
What impact does CVE-2026-59995 have on file downloads?
CVE-2026-59995 can cause improper constraints on file downloads, potentially allowing an attacker to control where files are saved.