OpenBSD's vulnerability footprint, concentrated in a small set of carefully maintained core products, carries outsized significance in the infrastructure landscape owing to the operating system's adoption in security-sensitive deployments and the widespread distribution of its derived components such as OpenSSH, LibreSSL, and OpenSMTPD. Despite a modest product count, the vendor's disclosures span a large volume of CVEs and frequently acquire public exploit code, reflecting both the scrutiny these widely trusted security tools attract and their role in critical network boundaries. Vulnerabilities recur through memory-safety and input-validation weakness classes, including buffer-boundary conditions, improper input validation, and information-disclosure flaws that are characteristic of low-level system software and cryptographic libraries. Defenders should monitor this vendor's advisories closely for patches affecting SSH, TLS, and mail infrastructure components, as updates often propagate rapidly through automated deployment pipelines; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openbsd over time
Signals from CVEs in this vendor scope (357 CVEs).
357 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7247CRITICAL smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP sessio | Jan 29, 2020 | 9.8 | 99 | YES | YES |
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2018-15473MEDIUM OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be | Aug 17, 2018 | 5.3 | 86 | NO | YES |
CVE-2016-6210MEDIUM sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remo | Feb 13, 2017 | 5.9 | 84 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2003-0466CRITICAL Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug | Aug 27, 2003 | 9.8 | 81 | NO | YES |
CVE-2003-0190MEDIUM OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine va | May 12, 2003 | 5.0 | 78 | NO | YES |
CVE-2023-38408CRITICAL The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-con | Jul 20, 2023 | 9.8 | 77 | NO | NO |
CVE-2023-25136MEDIUM OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unaut | Feb 3, 2023 | 6.5 | 71 | NO | NO |
CVE-2007-5365HIGH Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote a | Oct 11, 2007 | 7.2 | 71 | NO | YES |
Signals from CVEs in this vendor scope (357 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openbsd.
Media articles that mention a CVE ID that affects a product developed by Openbsd — matched by CVE ID, not by vendor name.