boks Index
Docs Releases

openssh

7 tools · 1 release line

Secure remote login, file transfer and key management over SSH. Each tool carries its own sandbox boundary — they are not the same.

boks ssh-add
boks ssh-agent
boks ssh-keygen
boks ssh-keyscan
boks scp
boks sftp
boks ssh

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

capabilities differ between them

Tool Capabilities Seccomp Findings Image Description
showing ssh-add ssh-agent ssh-keygen ssh-keyscan scp sftp ssh from openssh@latest → 10.2p1 stable

Findings

H1M2L3

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-55655 ↗ M 6.1 openssh A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections.
CVE-2026-73282 ↗ M 4.8 openssh In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CVE-2026-55654 ↗ L 3.7 openssh A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the…
CVE-2026-73281 ↗ L 3.5 openssh In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
CVE-2026-73283 ↗ L 2.5 openssh In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

2 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-54876 openssl not affected · vex

These are the findings of openssh-add, which ships ssh-add. Other tools in this project ship in different images and carry different findings. boks reports and gates; it never edits an image to clear a finding.

Findings

H1M2L3

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-55655 ↗ M 6.1 openssh A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections.
CVE-2026-73282 ↗ M 4.8 openssh In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CVE-2026-55654 ↗ L 3.7 openssh A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the…
CVE-2026-73281 ↗ L 3.5 openssh In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
CVE-2026-73283 ↗ L 2.5 openssh In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

2 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-54876 openssl not affected · vex

These are the findings of openssh-agent, which ships ssh-agent. Other tools in this project ship in different images and carry different findings. boks reports and gates; it never edits an image to clear a finding.

Findings

H2M2L3

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-55655 ↗ M 6.1 openssh A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections.
CVE-2026-73282 ↗ M 4.8 openssh In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CVE-2026-55654 ↗ L 3.7 openssh A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the…
CVE-2026-73281 ↗ L 3.5 openssh In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
CVE-2026-73283 ↗ L 2.5 openssh In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex

These are the findings of openssh-keygen, which ships ssh-keygen. Other tools in this project ship in different images and carry different findings. boks reports and gates; it never edits an image to clear a finding.

Findings

H1M2L3

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-55655 ↗ M 6.1 openssh A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections.
CVE-2026-73282 ↗ M 4.8 openssh In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CVE-2026-55654 ↗ L 3.7 openssh A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the…
CVE-2026-73281 ↗ L 3.5 openssh In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
CVE-2026-73283 ↗ L 2.5 openssh In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

2 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-54876 openssl not affected · vex

These are the findings of openssh-keyscan, which ships ssh-keyscan. Other tools in this project ship in different images and carry different findings. boks reports and gates; it never edits an image to clear a finding.

Findings

M2L3

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-55655 ↗ M 6.1 openssh A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections.
CVE-2026-73282 ↗ M 4.8 openssh In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CVE-2026-55654 ↗ L 3.7 openssh A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the…
CVE-2026-73281 ↗ L 3.5 openssh In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
CVE-2026-73283 ↗ L 2.5 openssh In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

These are the findings of openssh-scp, which ships scp. Other tools in this project ship in different images and carry different findings. boks reports and gates; it never edits an image to clear a finding.

Findings

M2L3

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-55655 ↗ M 6.1 openssh A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections.
CVE-2026-73282 ↗ M 4.8 openssh In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CVE-2026-55654 ↗ L 3.7 openssh A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the…
CVE-2026-73281 ↗ L 3.5 openssh In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
CVE-2026-73283 ↗ L 2.5 openssh In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

These are the findings of openssh-sftp, which ships sftp. Other tools in this project ship in different images and carry different findings. boks reports and gates; it never edits an image to clear a finding.

Findings

H2M2L3

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-55655 ↗ M 6.1 openssh A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections.
CVE-2026-73282 ↗ M 4.8 openssh In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CVE-2026-55654 ↗ L 3.7 openssh A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the…
CVE-2026-73281 ↗ L 3.5 openssh In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys.
CVE-2026-73283 ↗ L 2.5 openssh In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex

These are the findings of openssh-ssh, which ships ssh. Other tools in this project ship in different images and carry different findings. boks reports and gates; it never edits an image to clear a finding.

Composition

default nothing — stands alone
runtime none — self-contained
composes not used as a runtime

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime none — self-contained
composes not used as a runtime

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime none — self-contained
composes not used as a runtime

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime none — self-contained
composes not used as a runtime

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + ssh
runtime none — self-contained
composes ssh

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + ssh
runtime none — self-contained
composes ssh

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime none — self-contained
composes not used as a runtime

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/openssh-add:10.2p1
digest
platforms
size 8 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/openssh-agent:10.2p1
digest
platforms
size 8 MB unpacked · 1 layer
base scratch
signed not signed
last scan

Image

image ghcr.io/boks-sh/openssh-keygen:10.2p1
digest
platforms
size 9 MB unpacked · 1 layer
base scratch
signed not signed
last scan

Image

image ghcr.io/boks-sh/openssh-keyscan:10.2p1
digest
platforms
size 8 MB unpacked · 1 layer
base scratch
signed not signed
last scan

Image

image ghcr.io/boks-sh/openssh-scp:10.2p1
digest
platforms
size <1 MB unpacked · 1 layer
base scratch
signed not signed
last scan

Image

image ghcr.io/boks-sh/openssh-sftp:10.2p1
digest
platforms
size <1 MB unpacked · 1 layer
base scratch
signed not signed
last scan

Image

image ghcr.io/boks-sh/openssh-ssh:10.2p1
digest
platforms
size 11 MB unpacked · 1 layer
base scratch
signed not signed
last scan

Sandbox boundary

ssh-add

capabilities

ro

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.ssh

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

ssh-agent

capabilities

ro

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

ssh-keygen

capabilities

rw

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.ssh · writable

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

ssh-keyscan

capabilities

netro

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

scp

capabilities

netrw

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.ssh
  • ~/.ssh/known_hosts · writable

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

sftp

capabilities

netrw

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.ssh
  • ~/.ssh/known_hosts · writable

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

ssh

capabilities

netro

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.ssh
  • ~/.ssh/known_hosts · writable

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

attestation arm64 — none amd64 — none
scan report arm64 ↗ amd64 ↗ grype ·

Every image ships a full SBOM. Nothing here is a claim you have to take on trust. Build attestation is not published yet.

Provenance

attestation arm64 — none amd64 — none
scan report arm64 ↗ amd64 ↗ grype ·

Every image ships a full SBOM. Nothing here is a claim you have to take on trust. Build attestation is not published yet.

Provenance

attestation arm64 — none amd64 — none
scan report arm64 ↗ amd64 ↗ grype ·

Every image ships a full SBOM. Nothing here is a claim you have to take on trust. Build attestation is not published yet.

Provenance

attestation arm64 — none amd64 — none
scan report arm64 ↗ amd64 ↗ grype ·

Every image ships a full SBOM. Nothing here is a claim you have to take on trust. Build attestation is not published yet.

Provenance

attestation arm64 — none amd64 — none
scan report arm64 ↗ amd64 ↗ grype ·

Every image ships a full SBOM. Nothing here is a claim you have to take on trust. Build attestation is not published yet.

Provenance

attestation arm64 — none amd64 — none
scan report arm64 ↗ amd64 ↗ grype ·

Every image ships a full SBOM. Nothing here is a claim you have to take on trust. Build attestation is not published yet.

7 findings across this project at latest. Counted once per advisory across every image the project builds.