
CVE-2026-60000: OpenSSH <10.4 allows unlimited auth attempts when GSSAPI is enabled. MaxAuthTries was ignored. Resource exhaustion, no credentials required. NIST: 7.5 HIGH.
Post summary
The post reports that OpenSSH versions below 10.4 allow unlimited authentication attempts when GSSAPI is enabled, ignoring MaxAuthTries and causing resource exhaustion without requiring credentials.


