CVE Tools

Openbsd-project

30 CVEs tracked since 2015. Since Aug 2015, none of them reached CISA KEV.

Openbsd-project CVEs per month

Aug 2015 to Dec 2023. Point at a month, or focus the strip and use the arrow keys.
Openbsd-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0850
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-0130
2016-02null or fewer
2016-0310
2016-04null or fewer
2016-0510
2016-06null or fewer
2016-0710
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-1210
2017-01null or fewer
2017-02null or fewer
2017-03100
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-1020
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-0820
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-1240

Products

The products that kept showing up in Openbsd-project's monthly top three, with their CVEs summed over those months.

  1. Openssh188 months
  2. OpenBSD112 months
  3. Opensmtpd11 month
  4. Openssh Server11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Openbsd-project.

  1. CVE-2026-56099OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input5.3
  2. CVE-2026-41285In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd...4.3
  3. CVE-2026-35414OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma ch...4.2
  4. CVE-2026-32772telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.3.4
  5. CVE-2025-61985ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.3.6
  6. CVE-2025-61984ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untr...3.6
  7. BDU:2025-10376Уязвимость функции ssh_packet_read_poll2() файла packet.c средства криптографической защиты OpenSSH, позволяющая нарушителю вызвать отказ в обслуживании7.5
  8. CVE-2025-32728In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.4.3
  9. CVE-2025-30334OpenBSD wg(4) kernel crash6.5
  10. CVE-2025-26466Openssh: denial-of-service in openssh5.9
  11. CVE-2025-26465Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled6.8
  12. CVE-2024-11148OpenBSD httpd(8) null dereference7.5
  13. CVE-2024-10934OpenBSD NFS double-free vulnerability9.8
  14. CVE-2024-6409Openssh: possible remote code execution due to a race condition in signal handling affecting red hat enterprise linux 97.0
  15. CVE-2024-39894OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing ...7.5

The record

Peak rank
#30 in Aug 2015
Busiest month shown
Mar 2017, 10 CVEs
Months with a KEV entry
0 since Aug 2015
Monthly snapshots
10 since 2015
Openbsd-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store