Skip to content
COOEY

FAIL › dossier

openbsd

VENDOR

· dossier confidence 20%

OpenBSD is a security-focused operating system with a strong community reputation but a history of critical vulnerabilities in core components like OpenSMTPD and OpenSSH. Its track record shows high and critical flaws in network services and cryptographic handling, requiring vigilant patching and configuration management.

PROFILE
CategoryOperating System VendorWhat they doOpenBSD is a Unix-like operating system focused on security and simplicity, primarily used in servers and network appliances. Websitehttps://www.openbsd.org ↗
SECURITY POSTURE

OpenBSD maintains a strong security reputation but has experienced high and critical vulnerabilities in core components like OpenSMTPD and OpenSSH, including remote code execution and use-after-free flaws.

Notable failures
  • CVE-2020-7247: OpenSMTPD RCE
  • CVE-2023-28531: OpenSSH smartcard key handling
  • CVE-2026-60002: OpenSSH use-after-free
Patterns: Core component vulnerabilities in network services; Smartcard and cryptographic key handling issues
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2020-7247 high A remote code execution flaw in OpenSMTPD allowed attackers to run arbitrary commands as root via a crafted SMTP session.
2026-07-08 CVE-2026-60002 high ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
2023-03-17 CVE-2023-28531 critical CVE-2023-28531: ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the inten
DOSSIER SOURCES
Open questions: OpenBSD's exact founding year and headquarters location are not explicitly stated in the provided web evidence. · The exact size and ownership structure of OpenBSD are not explicitly stated in the provided web evidence.
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-29 04:09:19.780620+00:00