CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73283

lowCVSS 2.5covered by 2 sourcesfirst seen 2026-08-11
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

CSIRTS triage

What
The restrict keyword in authorized_keys does not properly restrict tunnel forwarding as intended.
Who is affected
Systems running OpenSSH versions before 10.5 using restrict keyword for access control.
Urgency
Low severity (CVSS 2.5); not exploited; affects only systems relying on restrict for tunnel control.
Action
Upgrade OpenSSH to version 10.5 or later to enforce restrict keyword properly.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-73283

Get an email if CVE-2026-73283 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-73283

CVE.org record

Embed the live status

CVE-2026-73283 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73283 status](https://www.csirts.com/badge/CVE-2026-73283)](https://www.csirts.com/cve/CVE-2026-73283)