CVE-2026-59997: Medium severity OpenSSH OpenSSH vulnerability
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.8p1-9 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.4p1-1 - Upgrade
Upgrade
OpenSSH sshd (internal-sftp)to a version that resolves this vulnerability.Fixed in 10.4 - Compensating control
Ensure any use of sshd SFTP command-line arguments does not rely on arguments beyond the first 9 when running OpenSSH versions prior to 10.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59997?
The severity of CVE-2026-59997 is medium with a score of 4.2.
How do I fix CVE-2026-59997?
To mitigate CVE-2026-59997, upgrade to OpenSSH version 10.4 or later.
What are the potential impacts of CVE-2026-59997?
CVE-2026-59997 could allow for the misconfiguration of security properties in SFTP connections due to restricted command-line argument recognition.
Which version of OpenSSH is affected by CVE-2026-59997?
OpenSSH versions prior to 10.4 are affected by CVE-2026-59997.
What is the nature of the vulnerability in CVE-2026-59997?
CVE-2026-59997 is a vulnerability in the internal-sftp that limits the recognition of command-line arguments, impacting SFTP security.