What happened
The forwarding path is insufficiently constrained in a narrow agent-forwarding configuration. A remote actor with an existing authenticated path may influence how a local socket is resolved.
Affected versions
OpenSSH Agent: ≤ 9.9p1 Fixed: 10.0p1.
Why it matters
Agent forwarding often bridges trust boundaries. A validation failure can expose credentials or administrative workflows beyond the intended host.
Detection & mitigation
- Upgrade to OpenSSH 10.0p1 or later.
- Disable agent forwarding where it is not operationally required.
- Restrict forwarding to explicitly trusted hosts and review agent socket access.
Public PoC references
RepositoryAuthorFirst seenReference
openssh-forwarding-validationresearch-labSep 1, 2026CandidateSource timeline
Initial record observedView source ↗
ExploitAlert record refreshed
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.