JLSEC-2025-8 Low 3.6
ssh in OpenSSH before 10.1 allows the '`\0`' character in an `ssh://` URI, potentially leading to code...
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
References
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://github.com/advisories/GHSA-8gmf-r74v-362p
- https://marc.info/?l=openssh-unix-dev&m=175974522032149&w=2
- https://nvd.nist.gov/vuln/detail/CVE-2025-61985
- https://www.openssh.com/releasenotes.html#10.1p1
- https://www.openwall.com/lists/oss-security/2025/10/06/1