FR
live
vendor

Libssh

5
vulnerabilities tracked
21 July 2026
latest publication
cve

Vulnerability watch

idvulnerabilityseveritypublished
CVE-2026-15370A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.Libssh High CVSS 7.3 21/07 CVE-2026-59847A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.Libssh High CVSS 7.5 21/07 CVE-2026-59849A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.Libssh High CVSS 7.5 21/07 CVE-2026-59850A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.Libssh High CVSS 7.5 21/07 CVE-2026-59851A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.Libssh High CVSS 8.8 21/07

Type at least two characters.

navigate open esc dismiss