OpenSSH <10.0: DisableForwarding fails to disable X11/agent forwarding
CVE-2025-32728 Published on April 10, 2025

In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

NVD

Weakness Type

Expected Behavior Violation

A feature, API, or function does not perform according to its specification.


Products Associated with CVE-2025-32728

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-32728 are published in these products:

 
 
 

Affected Versions

OpenBSD OpenSSH:

Exploit Probability

EPSS
0.27%
Percentile
50.43%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.