CVE-2026-48711: Bracketed Hostname Option Injectioncve-2026-48711-bracketed-hostname-option-injection
Bracketed host parsing removes brackets without validating that the extracted hostname does not begin with a hyphen ('-'). This can allow command-line argument injection if the hostname is passed to external commands such as ssh.