source-audit

1 article in this topic.

April 2026

1 article
  1. CVE-2026-35414: Three Bugs, One Commit, and Two More Nobody Mentioned

    CVE-2026-35414 is a certificate principal matching bypass in OpenSSH before 10.3. The advisory says one bug. We found three - a comma-splitting misuse, an empty-principals wildcard, and a reversed match_pattern call - all hiding in the same commit. Two are independently exploitable for authentication bypass. We built working PoCs for both, then kept reading and found two more undocumented issues: a PermitListen bypass via Unix socket forwarding and a KRL revocation gap for serial-zero certificates.

    18 min read