Dropbear Ssh Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 21
    Known Exploited: 0
    2
    Critical Level Threats
    7
    High Level Threats
    12
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-47203

    dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.

    Last Modified: Apr 15, 2026
    Published: May 07, 2025

    CVE-2023-48795

    ssh: Prefix truncation attack on Binary Packet Protocol (BPP)

    Last Modified: May 12, 2026
    Published: Dec 18, 2023

    CVE-2021-36369

    An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass. Thus, it allows an attacker to abuse a forwarded agent for logging on to another server unnoticed.

    Last Modified: May 15, 2025
    Published: Oct 12, 2022

    CVE-2020-36254

    scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.

    Last Modified: Dec 03, 2025
    Published: Feb 25, 2021

    CVE-2019-12953

    Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.

    Last Modified: Nov 21, 2024
    Published: Dec 30, 2020
    Items Per Page