Known Vulnerabilities for products from Libssh

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Libssh".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-59851 json Not Provided 2026-07-21 2026-07-22
CVE-2026-59850 json Not Provided 2026-07-21 2026-07-22
CVE-2026-59849 json A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to... Not Provided 2026-07-21 2026-07-30
CVE-2026-59848 json A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queue... Not Provided 2026-07-21 2026-07-30
CVE-2026-59847 json A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove ... Not Provided 2026-07-21 2026-07-30
CVE-2026-59846 json Not Provided 2026-07-21 2026-07-23
CVE-2026-59845 json A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cle... Not Provided 2026-07-21 2026-07-30
CVE-2026-59844 json A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, c... Not Provided 2026-07-21 2026-07-30
CVE-2026-59843 json A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, cau... Not Provided 2026-07-21 2026-07-30
CVE-2026-59842 json A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the ... Not Provided 2026-07-21 2026-07-30
CVE-2026-15370 json A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation... Not Provided 2026-07-21 2026-07-30
CVE-2026-0968 json A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malfor... Not Provided 2026-03-26 2026-05-19
CVE-2026-0967 json A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft sp... Not Provided 2026-03-26 2026-05-19
CVE-2026-0966 json A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-lengt... Not Provided 2026-03-26 2026-05-19
CVE-2026-0965 json A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can ex... Not Provided 2026-03-26 2026-05-19
CVE-2026-0964 json A malicious SCP server can send unexpected paths that could make the client application override local files outside of worki... Not Provided 2026-03-26 2026-05-19
CVE-2025-14821 json A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure She... Not Provided 2026-04-07 2026-06-30
CVE-2025-8114 json A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchan... Not Provided 2025-07-24 2026-06-30
CVE-2025-5987 json A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the hea... Not Provided 2025-07-07 2026-06-30
CVE-2025-5449 json A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length chec... Not Provided 2025-07-25 2026-06-30

Known software with vulnerabilities from Libssh

Type Vendor Product Version
ApplicationLibsshLibssh0.4.7

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report