OpenSSH <10.0: DisableForwarding fails to disable X11/agent forwarding
CVE-2025-32728 Published on April 10, 2025
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
Weakness Type
Expected Behavior Violation
A feature, API, or function does not perform according to its specification.
Products Associated with CVE-2025-32728
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-32728 are published in these products:
Affected Versions
OpenBSD OpenSSH:- Version 7.4 and below 10.0 is affected.
Exploit Probability
EPSS
0.27%
Percentile
50.43%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.