PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
Metrics
Affected Vendors & Products
References
History
Mon, 25 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Residual Trust Status Leak in PuTTY Telnet Sessions |
Mon, 25 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session. | |
| First Time appeared |
Putty
Putty putty |
|
| Weaknesses | CWE-451 | |
| CPEs | cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Putty
Putty putty |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-25T20:16:31.485Z
Reserved: 2026-05-25T20:16:30.998Z
Link: CVE-2026-48851
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T21:30:06Z