OpenSSH Connection Multiplexing Confirmation Vulnerability in Proxy Mode

Vulnerability

A vulnerability exists in OpenSSH versions prior to 10.3, where connection multiplexing confirmation is omitted for proxy-mode multiplexing sessions. This issue can lead to unintended behavior in how multiplexed connections are managed, potentially causing disruptions in session handling or resource allocation.

Impact

The lack of proper confirmation for connection multiplexing in proxy mode can lead to issues with session management, such as improper handling of multiplexed connections or resource allocation, which could disrupt user workflows or application performance.

Remediation

Users can upgrade to OpenSSH 10.3 or later, where this vulnerability has been addressed.

Added: Apr 2, 2026, 5:41 PM
Updated: Apr 2, 2026, 5:41 PM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
0.6
exploitability
5.0
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.