In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
[
{
"id": "CVE-2025-32728-3d303bb6",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"target": {
"file": "session.c",
"function": "session_setup_x11fwd"
},
"digest": {
"function_hash": "133076491639203383823387614455115839010",
"length": 2048.0
},
"source": "https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367"
},
{
"id": "CVE-2025-32728-64280ae0",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"target": {
"file": "session.c",
"function": "session_auth_agent_req"
},
"digest": {
"function_hash": "151169046701137936850466914400687768049",
"length": 428.0
},
"source": "https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367"
},
{
"id": "CVE-2025-32728-8bcee90d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "session.c"
},
"digest": {
"line_hashes": [
"302129403808892202751107050716447255615",
"227186618945793496493460375356702822421",
"61277606599405778295293498416605726251",
"39052513940640503578487586278620661415",
"171785806372956002748894980549115022364",
"53875906461956996569308087778751541414",
"211306792223610455392567591025373616519",
"240962318817132672213255136405283026374",
"84505436348310955167133086453229315999"
],
"threshold": 0.9
},
"source": "https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367"
}
]