Page 1 of 1

CVE-2026-59997 - OpenSSH internal-sftp Argument Parsing Vulnerability

Posted: Wed Jul 08, 2026 8:25 am
by Starburst-David
CVE ID: CVE-2026-59997
Published: July 8, 2026
Description: internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
Severity: 4.2 | MEDIUM

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-59997