Vulnerability Description
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Putty | Putty | >= 0.77, < 0.84 |
Related Weaknesses (CWE)
References
- https://lists.tartarus.org/pipermail/putty-announce/2026/000042.htmlRelease Notes
- https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/telnet-trust-sigil.hPatchVendor Advisory
FAQ
What is CVE-2026-48851?
CVE-2026-48851 is a vulnerability with a CVSS score of 3.1 (LOW). PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
How severe is CVE-2026-48851?
CVE-2026-48851 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48851?
Check the references section above for vendor advisories and patch information. Affected products include: Putty Putty.