Where
-Infinity
0

oss-seclibssh 0.12.1 and 0.11.5 security leases

libssh libsshLibssh: libssh: stack buffer overflow in sftp server longname construction

Risk 63
Severity
6.7
First published (updated )

libssh libsshLibssh: libssh: denial of service via unchecked proxycommand fork() failure

Risk 31
Severity
5.3
First published (updated )

libssh libsshLibssh: libssh: denial of service via oversized sftp read length

Risk 40
Severity
6.5
First published (updated )

libssh libsshA flaw was found in libssh username handling for ProxyCommand expansion. The ssh_check_username_synt…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

libssh libsshLibssh: libssh: information disclosure via proxycommand %r username expansion

Risk 27
Severity
3.9
First published (updated )

libssh libsshLibssh: libssh: denial of service via sftp responses with unknown request ids

Risk 28
Severity
5.3
First published (updated )

libssh libsshLibssh: libssh: authentication bypass via missing gssapi principal check

Risk 83
Severity
8.8
First published (updated )

libssh libsshLibssh: libssh: denial of service via automatic certificate authentication loop

Risk 18
Severity
3.1
First published (updated )

libssh libsshLibssh: libssh: use-after-free via data callbacks on closed channels

Risk 24
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

libssh libsshA flaw was found in libssh server-side GSSAPIKeyExchange authorization. In ssh_packet_userauth_reque…

Risk 33
Severity
7
First published (updated )

libssh libsshA flaw was found in libssh automatic certificate-based public key authentication. In ssh_userauth_pu…

Risk 5
Severity
1
First published (updated )

libssh libsshLibssh: libssh: denial of service via zero advertised channel packet size

Risk 40
Severity
6.5
First published (updated )

libssh libsshA flaw was found in libssh channel handling. In ssh_packet_channel_open() in src/messages.c and ssh_…

Risk 19
Severity
4
First published (updated )

libssh libsshLibssh: libssh: information disclosure via short gssapi curve25519 public key

Risk 21
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

libssh libsshA flaw was found in libssh in the server-side GSSAPI Curve25519 key exchange path in src/kex-gss.c. …

Risk 5
Severity
1
First published (updated )

libssh/libsshlibssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds

Risk 31
Severity
6.9
EPSS
0.10%
First published (updated )

libssh libsshLibssh: libssh: denial of service due to malformed sftp message

Risk 37
Severity
3.1
First published (updated )

libssh libsshA malicious SFTP server can send malformed longname field of the `SSH_FXP_NAME` message (file listin…

Risk 5
Severity
1
First published (updated )

libssh libsshLibssh: libssh: denial of service via inefficient regular expression processing

Risk 31
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

libssh libsshLibssh: libssh: denial of service via improper configuration file handling

Risk 18
Severity
3.3
First published (updated )

libssh libsshlibssh can try to open any file during configuration parsing, when misconfigured or when local attac…

Risk 5
Severity
1
First published (updated )

redhat Enterprise LinuxLibssh: improper sanitation of paths received from scp servers

Risk 45
Severity
6.3
First published (updated )

redhat Enterprise LinuxLibssh: libssh: denial of service via zero-length input in ssh_get_hexa()

Risk 54
Severity
8.2
First published (updated )

libssh libsshLibssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

libssh libsshAn insecure default configuration vulnerability exists in libssh on Windows systems where the librar…

Risk 5
Severity
1
First published (updated )

Microsoft azl3 libssh 0.10.6-3Libssh: memory exhaustion via repeated key exchange in libssh

Risk 17
Severity
3.1
First published (updated )

libssh libsshMemory Exhaustion vulnerability in the key exchange logic of the libssh library. When an authenticat…

Risk 5
Severity
1
First published (updated )

libssh libsshLibssh: null pointer dereference in libssh kex session id calculation

Risk 21
Severity
4.7
EPSS
0.01%
First published (updated )

libssh libsshNull Pointer Dereference

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203