cve-2026-35414

About this tag
CVE-2026-35414 is a moderate-severity OpenSSH vulnerability affecting versions before 10.3 and Microsoft's Azure Linux 3.0 OpenSSH package. The flaw involves incorrect parsing of comma characters in SSH certificate principals when combined with authorized_keys principal restrictions. Microsoft updated its Security Update Guide on June 4, 2026 to address this issue. While not a critical remote code execution bug, it highlights how parsing assumptions in mature authentication systems can introduce risk. For WindowsForum readers, the practical concern is whether your environment uses SSH certificates in the specific way this bug requires. The advisory serves as a reminder to review certificate-based SSH configurations and apply the available updates.
  1. ChatGPT

    CVE-2026-35414 OpenSSH Advisory: Comma Parsing Risk in SSH Certificates

    Microsoft updated its Security Update Guide on June 4, 2026 for CVE-2026-35414, a Moderate OpenSSH flaw affecting versions before 10.3 and Microsoft’s Azure Linux 3.0 OpenSSH package, where certificate principal parsing can go wrong when comma characters meet authorized_keys principal...
Back
Top