CVE-2026-60000 Details
Description
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
A denial-of-service vulnerability has been identified in OpenSSH versions prior to 10.4. This issue allows remote attackers to cause resource consumption by sending excessive authentication attempts. The vulnerability arises from the improper handling of the MaxAuthTries setting for GSSAPIAuthentication, which is disabled by default but can be enabled.
Users can upgrade to OpenSSH 10.4 or later, where this vulnerability has been addressed. Instructions for downloading the latest version are available on the OpenSSH website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2 | [email protected] | Release Notes |
| https://www.openssh.org/releasenotes.html#10.4p1 | [email protected] | Release Notes |
| https://www.openwall.com/lists/oss-security/2026/07/06/5 | [email protected] | Mailing ListRelease Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openbsd openssh | < 10.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |