There are 3 open security issues in trixie.
3 issues left for the package maintainer to handle:
- CVE-2026-48850:
(needs triaging)
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
- CVE-2026-48851:
(needs triaging)
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
- CVE-2026-48852:
(needs triaging)
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
You can find information about how to handle these issues in the security team's documentation.