CVE-2025-32728
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Affected products
OpenBSD · OpenSSHReferences
https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/013_ssh.patch.sighttps://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367https://lists.debian.org/debian-lts-announce/2025/05/msg00008.htmlhttps://lists.mindrot.org/pipermail/openssh-unix-dev/2025-April/041879.htmlhttps://security.netapp.com/advisory/ntap-20250425-0002/https://www.openssh.com/txt/release-10.0https://www.openssh.com/txt/release-7.4