rpm package
opensuse/sshfs&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/sshfs&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-48711 | Hig | 7.0 | < 3.7.6-1.1 | 3.7.6-1.1 | Aug 19, 2026 | SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path and find_base_path() removes the brackets, leaving a host value that begins with - and is passed directly to | |
| CVE-2026-47187 | Cri | 9.3 | < 3.7.6-1.1 | 3.7.6-1.1 | Aug 19, 2026 | SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes through FUSE for resolution by the client kernel agains |
- affected < 3.7.6-1.1fixed 3.7.6-1.1
SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path and find_base_path() removes the brackets, leaving a host value that begins with - and is passed directly to
- affected < 3.7.6-1.1fixed 3.7.6-1.1
SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes through FUSE for resolution by the client kernel agains