{"schema_version":1,"title":"Libssh vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 26 vulnerabilities in Libssh: 0 in the last 7 days and 11 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-59851, was published on 21 July 2026.","url":"https://junglewise.ai/threats/technologies/libssh","json_url":"https://junglewise.ai/threats/technologies/libssh.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/libssh","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":26,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":11,"last_365_days":17},"latest":[{"cve":"CVE-2026-59851","cvss":8.8,"slug":"cve-2026-59851-libssh-authentication-bypass-in-gssapikeyexchange","title":"libssh authentication bypass in GSSAPIKeyExchange","severity":"high","exploited":false,"published_at":"2026-07-21T15:16:37.897+00:00","url":"https://junglewise.ai/threats/cve-2026-59851-libssh-authentication-bypass-in-gssapikeyexchange"},{"cve":"CVE-2026-59850","cvss":4.3,"slug":"cve-2026-59850-libssh-use-after-free-in-channel-data-callbacks","title":"libssh use-after-free in channel data callbacks","severity":"medium","exploited":false,"published_at":"2026-07-21T15:16:37.773+00:00","url":"https://junglewise.ai/threats/cve-2026-59850-libssh-use-after-free-in-channel-data-callbacks"},{"cve":"CVE-2026-59849","cvss":3.1,"slug":"cve-2026-59849-libssh-infinite-loop-in-certificate-based-authentication","title":"libssh infinite loop in certificate-based authentication","severity":"low","exploited":false,"published_at":"2026-07-21T15:16:37.647+00:00","url":"https://junglewise.ai/threats/cve-2026-59849-libssh-infinite-loop-in-certificate-based-authentication"},{"cve":"CVE-2026-59848","cvss":5.3,"slug":"cve-2026-59848-libssh-denial-of-service-via-memory-exhaustion-in-sftp-client","title":"libssh denial of service via memory exhaustion in SFTP client","severity":"medium","exploited":false,"published_at":"2026-07-21T14:16:34.79+00:00","url":"https://junglewise.ai/threats/cve-2026-59848-libssh-denial-of-service-via-memory-exhaustion-in-sftp-client"},{"cve":"CVE-2026-59847","cvss":5.9,"slug":"cve-2026-59847-libssh-integrity-protection-bypass-in-openssl-aes-gcm-backend","title":"libssh integrity protection bypass in OpenSSL AES-GCM backend","severity":"medium","exploited":false,"published_at":"2026-07-21T14:16:34.657+00:00","url":"https://junglewise.ai/threats/cve-2026-59847-libssh-integrity-protection-bypass-in-openssl-aes-gcm-backend"},{"cve":"CVE-2026-59846","cvss":3.9,"slug":"cve-2026-59846-libssh-shell-metacharacter-injection-in-proxycommand-username","title":"libssh shell metacharacter injection in ProxyCommand username expansion","severity":"low","exploited":false,"published_at":"2026-07-21T13:17:18.143+00:00","url":"https://junglewise.ai/threats/cve-2026-59846-libssh-shell-metacharacter-injection-in-proxycommand-username"},{"cve":"CVE-2026-59845","cvss":5.3,"slug":"cve-2026-59845-libssh-denial-of-service-via-unchecked-fork-failure-in","title":"libssh denial of service via unchecked fork failure in ProxyCommand","severity":"medium","exploited":false,"published_at":"2026-07-21T12:18:58.103+00:00","url":"https://junglewise.ai/threats/cve-2026-59845-libssh-denial-of-service-via-unchecked-fork-failure-in"},{"cve":"CVE-2026-59844","cvss":6.5,"slug":"cve-2026-59844-libssh-denial-of-service-via-oversized-sftp-read-length","title":"libssh denial of service via oversized SFTP read length","severity":"medium","exploited":false,"published_at":"2026-07-21T12:18:57.973+00:00","url":"https://junglewise.ai/threats/cve-2026-59844-libssh-denial-of-service-via-oversized-sftp-read-length"},{"cve":"CVE-2026-59843","cvss":6.5,"slug":"cve-2026-59843-libssh-denial-of-service-via-zero-maximum-packet-size","title":"libssh denial of service via zero maximum packet size","severity":"medium","exploited":false,"published_at":"2026-07-21T12:18:57.86+00:00","url":"https://junglewise.ai/threats/cve-2026-59843-libssh-denial-of-service-via-zero-maximum-packet-size"},{"cve":"CVE-2026-59842","cvss":3.7,"slug":"cve-2026-59842-libssh-out-of-bounds-read-in-gssapi-curve25519-key-exchange","title":"libssh out-of-bounds read in GSSAPI Curve25519 key exchange","severity":"low","exploited":false,"published_at":"2026-07-21T12:18:57.727+00:00","url":"https://junglewise.ai/threats/cve-2026-59842-libssh-out-of-bounds-read-in-gssapi-curve25519-key-exchange"},{"cve":"CVE-2026-15370","cvss":6.7,"slug":"cve-2026-15370-libssh-stack-buffer-overflow-in-sftp-server-directory-listing","title":"libssh stack buffer overflow in SFTP server directory listing","severity":"medium","exploited":false,"published_at":"2026-07-21T09:16:53.683+00:00","url":"https://junglewise.ai/threats/cve-2026-15370-libssh-stack-buffer-overflow-in-sftp-server-directory-listing"},{"cve":"CVE-2025-14821","cvss":7.8,"epss":0.0013,"slug":"cve-2025-14821-libssh-insecure-default-configuration-on-windows","title":"libssh insecure default configuration on Windows","severity":"high","exploited":false,"published_at":"2026-04-07T17:16:25.433+00:00","url":"https://junglewise.ai/threats/cve-2025-14821-libssh-insecure-default-configuration-on-windows"},{"cve":"CVE-2026-0968","cvss":3.1,"epss":0.0001,"slug":"cve-2026-0968-libssh-heap-out-of-bounds-read-in-sftp-parse-longname","title":"libssh heap out-of-bounds read in sftp_parse_longname","severity":"low","exploited":false,"published_at":"2026-03-26T21:17:01.15+00:00","url":"https://junglewise.ai/threats/cve-2026-0968-libssh-heap-out-of-bounds-read-in-sftp-parse-longname"},{"cve":"CVE-2026-0967","cvss":5.5,"epss":0.0003,"slug":"cve-2026-0967-libssh-redos-in-match-pattern-function","title":"libssh ReDoS in match_pattern function","severity":"medium","exploited":false,"published_at":"2026-03-26T21:17:00.97+00:00","url":"https://junglewise.ai/threats/cve-2026-0967-libssh-redos-in-match-pattern-function"},{"cve":"CVE-2026-0966","cvss":8.2,"epss":0.0005,"slug":"cve-2026-0966-libssh-denial-of-service-in-ssh-get-hexa-function","title":"libssh denial of service in ssh_get_hexa function","severity":"high","exploited":false,"published_at":"2026-03-26T21:17:00.783+00:00","url":"https://junglewise.ai/threats/cve-2026-0966-libssh-denial-of-service-in-ssh-get-hexa-function"},{"cve":"CVE-2026-0965","cvss":3.3,"epss":0.0001,"slug":"cve-2026-0965-libssh-denial-of-service-via-arbitrary-file-access-in","title":"libssh Denial of Service via arbitrary file access in configuration parsing","severity":"low","exploited":false,"published_at":"2026-03-26T21:17:00.607+00:00","url":"https://junglewise.ai/threats/cve-2026-0965-libssh-denial-of-service-via-arbitrary-file-access-in"},{"cve":"CVE-2026-0964","cvss":6.3,"epss":0.0002,"slug":"cve-2026-0964-libssh-scp-path-traversal-in-ssh-scp-pull-request","title":"libssh SCP path traversal in ssh_scp_pull_request","severity":"medium","exploited":false,"published_at":"2026-03-26T21:17:00.393+00:00","url":"https://junglewise.ai/threats/cve-2026-0964-libssh-scp-path-traversal-in-ssh-scp-pull-request"},{"cve":"CVE-2025-8277","cvss":3.1,"epss":0.0005,"slug":"cve-2025-8277-libssh-memory-exhaustion-via-repeated-key-exchange-guesses","title":"libssh memory exhaustion via repeated key exchange guesses","severity":"low","exploited":false,"published_at":"2025-09-09T12:15:30.677+00:00","url":"https://junglewise.ai/threats/cve-2025-8277-libssh-memory-exhaustion-via-repeated-key-exchange-guesses"},{"cve":"CVE-2025-4877","cvss":4.5,"epss":0.0003,"slug":"cve-2025-4877-libssh-heap-overflow-in-binary-to-base64-conversion","title":"libssh heap overflow in binary to base64 conversion","severity":"medium","exploited":false,"published_at":"2025-08-20T13:15:28.89+00:00","url":"https://junglewise.ai/threats/cve-2025-4877-libssh-heap-overflow-in-binary-to-base64-conversion"},{"cve":"CVE-2025-5449","cvss":6.5,"epss":0.0074,"slug":"cve-2025-5449-libssh-integer-overflow-in-sftp-server-message-decoding","title":"libssh integer overflow in SFTP server message decoding","severity":"medium","exploited":false,"published_at":"2025-07-25T18:15:26.967+00:00","url":"https://junglewise.ai/threats/cve-2025-5449-libssh-integer-overflow-in-sftp-server-message-decoding"},{"cve":"CVE-2025-8114","cvss":4.7,"epss":0.0003,"slug":"cve-2025-8114-libssh-null-pointer-dereference-in-kex-session-id-calculation","title":"libssh NULL pointer dereference in KEX session ID calculation","severity":"medium","exploited":false,"published_at":"2025-07-24T15:15:27.117+00:00","url":"https://junglewise.ai/threats/cve-2025-8114-libssh-null-pointer-dereference-in-kex-session-id-calculation"},{"cve":"CVE-2025-4878","cvss":3.6,"epss":0.001,"slug":"cve-2025-4878-libssh-uninitialized-variable-in-privatekey-from-file","title":"libssh uninitialized variable in privatekey_from_file","severity":"low","exploited":false,"published_at":"2025-07-22T15:15:36.307+00:00","url":"https://junglewise.ai/threats/cve-2025-4878-libssh-uninitialized-variable-in-privatekey-from-file"},{"cve":"CVE-2025-5987","cvss":8.1,"epss":0.0144,"slug":"cve-2025-5987-libssh-improper-error-handling-in-chacha20-cipher-initialization","title":"libssh improper error handling in ChaCha20 cipher initialization","severity":"high","exploited":false,"published_at":"2025-07-07T15:15:28.18+00:00","url":"https://junglewise.ai/threats/cve-2025-5987-libssh-improper-error-handling-in-chacha20-cipher-initialization"},{"cve":"CVE-2025-5351","cvss":6.5,"epss":0.0035,"slug":"cve-2025-5351-libssh-double-free-in-key-export-functionality","title":"libssh double free in key export functionality","severity":"medium","exploited":false,"published_at":"2025-07-04T09:15:37.1+00:00","url":"https://junglewise.ai/threats/cve-2025-5351-libssh-double-free-in-key-export-functionality"},{"cve":"CVE-2025-5372","cvss":5,"epss":0.0025,"slug":"cve-2025-5372-libssh-incorrect-return-code-handling-in-ssh-kdf","title":"libssh incorrect return code handling in ssh_kdf","severity":"medium","exploited":false,"published_at":"2025-07-04T06:15:24.93+00:00","url":"https://junglewise.ai/threats/cve-2025-5372-libssh-incorrect-return-code-handling-in-ssh-kdf"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":11},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Libssh","slug":"libssh","vendor":{"name":"Libssh","slug":"libssh","url":"https://junglewise.ai/threats/vendors/libssh"},"aliases":[],"category":"library","homepage":"https://www.libssh.org/","repo_url":"https://git.libssh.org/projects/libssh.git","description":"libssh is a multiplatform C library implementing the SSHv2 protocol on client and server side.","url":"https://junglewise.ai/threats/technologies/libssh"},"most_severe":[{"cve":"CVE-2026-59851","cvss":8.8,"slug":"cve-2026-59851-libssh-authentication-bypass-in-gssapikeyexchange","title":"libssh authentication bypass in GSSAPIKeyExchange","severity":"high","exploited":false,"published_at":"2026-07-21T15:16:37.897+00:00","url":"https://junglewise.ai/threats/cve-2026-59851-libssh-authentication-bypass-in-gssapikeyexchange"},{"cve":"CVE-2026-0966","cvss":8.2,"epss":0.0005,"slug":"cve-2026-0966-libssh-denial-of-service-in-ssh-get-hexa-function","title":"libssh denial of service in ssh_get_hexa function","severity":"high","exploited":false,"published_at":"2026-03-26T21:17:00.783+00:00","url":"https://junglewise.ai/threats/cve-2026-0966-libssh-denial-of-service-in-ssh-get-hexa-function"},{"cve":"CVE-2025-5987","cvss":8.1,"epss":0.0144,"slug":"cve-2025-5987-libssh-improper-error-handling-in-chacha20-cipher-initialization","title":"libssh improper error handling in ChaCha20 cipher initialization","severity":"high","exploited":false,"published_at":"2025-07-07T15:15:28.18+00:00","url":"https://junglewise.ai/threats/cve-2025-5987-libssh-improper-error-handling-in-chacha20-cipher-initialization"},{"cve":"CVE-2025-14821","cvss":7.8,"epss":0.0013,"slug":"cve-2025-14821-libssh-insecure-default-configuration-on-windows","title":"libssh insecure default configuration on Windows","severity":"high","exploited":false,"published_at":"2026-04-07T17:16:25.433+00:00","url":"https://junglewise.ai/threats/cve-2025-14821-libssh-insecure-default-configuration-on-windows"},{"cve":"CVE-2026-15370","cvss":6.7,"slug":"cve-2026-15370-libssh-stack-buffer-overflow-in-sftp-server-directory-listing","title":"libssh stack buffer overflow in SFTP server directory listing","severity":"medium","exploited":false,"published_at":"2026-07-21T09:16:53.683+00:00","url":"https://junglewise.ai/threats/cve-2026-15370-libssh-stack-buffer-overflow-in-sftp-server-directory-listing"},{"cve":"CVE-2025-5449","cvss":6.5,"epss":0.0074,"slug":"cve-2025-5449-libssh-integer-overflow-in-sftp-server-message-decoding","title":"libssh integer overflow in SFTP server message decoding","severity":"medium","exploited":false,"published_at":"2025-07-25T18:15:26.967+00:00","url":"https://junglewise.ai/threats/cve-2025-5449-libssh-integer-overflow-in-sftp-server-message-decoding"},{"cve":"CVE-2025-5351","cvss":6.5,"epss":0.0035,"slug":"cve-2025-5351-libssh-double-free-in-key-export-functionality","title":"libssh double free in key export functionality","severity":"medium","exploited":false,"published_at":"2025-07-04T09:15:37.1+00:00","url":"https://junglewise.ai/threats/cve-2025-5351-libssh-double-free-in-key-export-functionality"},{"cve":"CVE-2026-59844","cvss":6.5,"slug":"cve-2026-59844-libssh-denial-of-service-via-oversized-sftp-read-length","title":"libssh denial of service via oversized SFTP read length","severity":"medium","exploited":false,"published_at":"2026-07-21T12:18:57.973+00:00","url":"https://junglewise.ai/threats/cve-2026-59844-libssh-denial-of-service-via-oversized-sftp-read-length"},{"cve":"CVE-2026-59843","cvss":6.5,"slug":"cve-2026-59843-libssh-denial-of-service-via-zero-maximum-packet-size","title":"libssh denial of service via zero maximum packet size","severity":"medium","exploited":false,"published_at":"2026-07-21T12:18:57.86+00:00","url":"https://junglewise.ai/threats/cve-2026-59843-libssh-denial-of-service-via-zero-maximum-packet-size"},{"cve":"CVE-2026-0964","cvss":6.3,"epss":0.0002,"slug":"cve-2026-0964-libssh-scp-path-traversal-in-ssh-scp-pull-request","title":"libssh SCP path traversal in ssh_scp_pull_request","severity":"medium","exploited":false,"published_at":"2026-03-26T21:17:00.393+00:00","url":"https://junglewise.ai/threats/cve-2026-0964-libssh-scp-path-traversal-in-ssh-scp-pull-request"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}