The OpenSSH client and server are vulnerable to a pre-authentication denial-of-service attack: an asymmetric resource consumption of both memory and CPU. This vulnerability was introduced in August 2023 (shortly before OpenSSH 9.5p1).
https://www.securityweek.com/openssh-patches-vulnerabilities-allowing-mitm-dos-attacks/
https://thehackernews.com/2025/02/new-openssh-flaws-enable-man-in-middle.html