A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
CVE-2025-26465
Score 6.8 from GitHub Security Advisory published 2025-02-18. NVD baseline CVSS 6.8; sources differ by 0.0.
- 11 internet-exposed hosts are running an affected version right now
- Lower severity and no public exploit yet
A fix is available — apply it.
11 internet-exposed hosts are running an affected version of CVE-2025-26465 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 6.8
- EG Score
- 6.8(medium)
- EPSS
- 93.8%
- KEV
- Not listed
Published
February 18, 2025
Last Modified
July 14, 2026
Advisory Details (10)
Auto-updated Jul 14, 2026Full Disclosure: APPLE-SA-05-12-2025-3 macOS Sequoia 15.5
http://seclists.org/fulldisclosure/2025/May/7Full Disclosure: Re: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
http://seclists.org/fulldisclosure/2025/Feb/18oss-sec: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
https://seclists.org/oss-sec/2025/q1/1442344780 – (CVE-2025-26465) CVE-2025-26465 openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled
Affected: Red Hat Enterprise Linux 9 openssh Affected
https://bugzilla.redhat.com/show_bug.cgi?id=2344780How to apply mitigation for CVE-2025-26465? - Red Hat Customer Portal
Affected: Red Hat Enterprise Linux 7 and higher
https://access.redhat.com/solutions/7109879Affected: Red Hat Enterprise Linux 9.
https://access.redhat.com/errata/RHSA-2025:6993Affected: Red Hat Enterprise Linux 9.4 Extended Update Support.
https://access.redhat.com/errata/RHSA-2025:3837Affected: Red Hat Enterprise Linux 8.
https://access.redhat.com/errata/RHSA-2025:16823Vendor Advisories for CVE-2025-26465(5)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- CVE-2025-26465Microsoft Security Response Center (MSRC)Medium
Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
- RHSA-2025:16823Red Hat Product SecurityMedium
Red Hat Security Advisory: openssh security update
- RHSA-2025:8385Red Hat Product SecurityMedium
Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage
- RHSA-2025:6993Red Hat Product SecurityMedium
Red Hat Security Advisory: openssh security update
- RHSA-2025:3837Red Hat Product SecurityMedium
Red Hat Security Advisory: openssh security update
Patch Availability(6)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | ssh-askpass-gnome (1:9.7p1-7ubuntu4.2) @ oracular | 2026-05-21 | ubuntu |
| ubuntu | ssh-krb5 (1:7.2p2-4ubuntu2.10+esm7) @ xenial | 2026-05-21 | ubuntu |
| redhat | openssh-0:8.0p1-26.el8_10 | 2025-09-26 | redhat |
| redhat | discovery/discovery-server-rhel9:1.14.3-1748529279 | 2025-06-02 | redhat |
| redhat | openssh-0:8.7p1-45.el9 | 2025-05-13 | redhat |
| redhat | openssh-0:8.7p1-38.el9_4.5 | 2025-04-14 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(2)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 10× in last 7d / 42× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 102 total refreshes for this CVE.
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-21 15:24 UTCEPSS rescore
- 2026-07-20 17:07 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 02:28 UTCEPSS rescore
- 2026-07-19 02:28 UTCEPSS rescore
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-16 17:02 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-13 22:29 UTCEPSS rescore
- 2026-07-13 22:29 UTCEPSS rescore
- 2026-07-12 05:46 UTCEPSS rescore
- 2026-07-12 05:46 UTCEPSS rescore
- 2026-07-11 08:27 UTCEPSS rescore
- 2026-07-11 08:26 UTCEPSS rescore
- 2026-07-10 17:52 UTCOSV refresh
- 2026-07-09 19:09 UTCEPSS rescore
- 2026-07-08 15:14 UTCEPSS rescore
- 2026-07-07 13:45 UTCEPSS rescore
- 2026-07-06 16:26 UTCEPSS rescore
- 2026-07-06 02:22 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-07-06 02:22 UTCEPSS rescore
- 2026-07-05 02:30 UTCEPSS rescore
- 2026-07-04 06:30 UTCEPSS rescore
- 2026-07-01 15:06 UTCEPSS rescore
- 2026-06-30 23:21 UTCEPSS rescore
- 2026-06-30 23:21 UTCEPSS rescore
- 2026-06-29 14:06 UTCEPSS rescore
- 2026-06-28 04:55 UTCEPSS rescore
- 2026-06-28 04:55 UTCEPSS rescore
- 2026-06-27 03:08 UTCEPSS rescore
- 2026-06-27 03:08 UTCEPSS rescore
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-24 14:04 UTCEPSS rescore
- 2026-06-24 14:04 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-22 14:25 UTCEPSS rescore
- 2026-06-22 14:25 UTCEPSS rescore
- 2026-06-22 02:07 UTCOSV refresh
- 2026-06-19 19:25 UTCEPSS rescore
- 2026-06-19 19:25 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-17 17:52 UTCEPSS rescore
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-15 17:48 UTCEPSS rescore
- 2026-06-13 22:59 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-11 13:59 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-10 13:22 UTCEPSS rescore
- 2026-06-06 13:47 UTCEPSS rescore
- 2026-06-06 13:47 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 06:10 UTCEPSS rescore
- 2026-06-05 06:10 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-03 18:39 UTCOSV refresh
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-29 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-23 15:20 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-21 22:42 UTCEPSS rescore
- 2026-05-21 17:33 UTCEG score recompute
- 2026-05-21 17:33 UTCVendor advisory
- 2026-05-21 17:32 UTCGHSA enrichment
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 11:21 UTCEPSS rescore
- 2026-05-20 11:21 UTCEPSS rescore
- 2026-05-20 11:21 UTCEPSS rescore
- 2026-05-20 11:21 UTCEPSS rescore
Publicly available exploits
(1 reference)Working exploit code is in the public domain (1 GitHub PoC). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCrxerium/CVE-2025-26465First seen Feb 18, 2025
MitM attack allowing a malicious interloper to impersonate a legitimate server when a client attempts to connect to it
Open source ↗
Frequently asked(5)
What is CVE-2025-26465?
When was CVE-2025-26465 disclosed?
Is CVE-2025-26465 actively exploited?
What is the CVSS score of CVE-2025-26465?
How do I remediate CVE-2025-26465?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2025-26465
Is Your Infrastructure Affected by CVE-2025-26465?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.