CVE-2026-35385
ADVISORY - nistSummary
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Preservation of Permissions
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in