libssh records
45 published records for vendor libssh.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.2%
- Pre-auth RCE
- 5
- With a fix record
- 97.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference6
- CWE-399 Resource Management Errors3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read2
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
45 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2018-10933Weaponized | A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4.libssh · libssh · CWE-592 | Critical9.1 | — | 91.8% | Oct 17, 2018 |
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.5% | Dec 18, 2023 |
36Monitor | CVE-2019-14889No exploit | A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8.libssh · libssh · CWE-78 | High8.8 | — | 3.2% | Dec 10, 2019 |
35Monitor | CVE-2026-59851No exploit | Libssh: libssh: authentication bypass via missing gssapi principal checklibssh · libssh · CWE-863 | High8.8 | — | 0.5% | Jul 21, 2026 |
35Monitor | CVE-2025-5372No exploit | Libssh: incorrect return code handling in ssh_kdf() in libsshlibssh · libssh · CWE-682 | High8.8 | — | 0.5% | Jul 4, 2025 |
34Monitor | CVE-2012-4562No exploit | Multiple integer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (infinite loop or crash) and possibly libssh · libssh · CWE-189 | High7.5 | — | 12.8% | Nov 30, 2012 |
32Monitor | CVE-2012-4560No exploit | Multiple buffer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary clibssh · libssh · CWE-119 | High7.5 | — | 6.5% | Nov 30, 2012 |
32Monitor | CVE-2025-5987No exploit | Libssh: invalid return code for chacha20 poly1305 with openssl backendlibssh · libssh · CWE-393 | High8.1 | — | 1.6% | Jul 7, 2025 |
32Monitor | CVE-2026-0966No exploit | Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()libssh · libssh · CWE-124 | High8.2 | — | 0.6% | Mar 26, 2026 |
31Monitor | CVE-2015-3146No exploit | The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, wlibssh · libssh | High7.5 | — | 3.9% | Apr 13, 2016 |
31Monitor | CVE-2012-6063No exploit | Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (libssh · libssh · CWE-399 | High7.5 | — | 3.6% | Nov 30, 2012 |
30Monitor | CVE-2026-59850No exploit | Libssh: libssh: use-after-free via data callbacks on closed channelslibssh · libssh · CWE-416 | High7.5 | — | 0.6% | Jul 21, 2026 |
30Monitor | CVE-2026-59847No exploit | Libssh: libssh: integrity downgrade via openssl aes-gcm tag verificationlibssh · libssh · CWE-253 | High7.5 | — | 0.6% | Jul 21, 2026 |
30Monitor | CVE-2026-59849No exploit | Libssh: libssh: denial of service via automatic certificate authentication looplibssh · libssh · CWE-835 | High7.5 | — | 0.4% | Jul 21, 2026 |
29Monitor | CVE-2012-4559No exploit | Multiple double free vulnerabilities in the (1) agent_sign_data function in agent.c, (2) channel_request function in channels.c, (3) ssh_uselibssh · libssh · CWE-399 | Medium6.8 | — | 5.2% | Nov 30, 2012 |
29Monitor | CVE-2026-15370No exploit | Libssh: libssh: stack buffer overflow in sftp server longname constructionlibssh · libssh · CWE-121 | High7.3 | — | 0.2% | Jul 21, 2026 |
28Monitor | CVE-2025-14821No exploit | Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windowslibssh · libssh · CWE-427 | High7.0 | — | 0.1% | Apr 7, 2026 |
27Monitor | CVE-2021-3634No exploit | A flaw has been found in libssh in versions prior to 0.9.6.libssh · libssh · CWE-787 | Medium6.5 | — | 4.7% | Aug 31, 2021 |
27Monitor | CVE-2026-3731No exploit | libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-boundslibssh · libssh · CWE-119 | Medium6.9 | — | 1.2% | Mar 8, 2026 |
26Monitor | CVE-2023-1667No exploit | A NULL pointer dereference was found In libssh during re-keying with algorithm guessing.libssh · libssh · CWE-476 | Medium6.5 | — | 1.3% | May 26, 2023 |
26Monitor | CVE-2023-2283No exploit | A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signaturlibssh · libssh · CWE-287 | Medium6.5 | — | 1.1% | May 26, 2023 |
26Monitor | CVE-2023-3603No exploit | Processing sftp server read may cause null dereferencelibssh · libssh · CWE-476 | Medium6.5 | — | 0.9% | Jul 21, 2023 |
26Monitor | CVE-2025-5449No exploit | Libssh: integer overflow in libssh sftp server packet length validation leading to denial of servicelibssh · libssh · CWE-190 | Medium6.5 | — | 0.9% | Jul 25, 2025 |
26Monitor | CVE-2026-59843No exploit | Libssh: libssh: denial of service via zero advertised channel packet sizelibssh · libssh · CWE-835 | Medium6.5 | — | 0.7% | Jul 21, 2026 |
26Monitor | CVE-2026-59844No exploit | Libssh: libssh: denial of service via oversized sftp read lengthlibssh · libssh · CWE-789 | Medium6.5 | — | 0.7% | Jul 21, 2026 |
- CVE-2018-1093364This week
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4.
CriticalCVSS 9.1WeaponizedEPSS 92%libssh · libsshOct 17, 2018
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 94%ssh · sshDec 18, 2023
- CVE-2019-1488936Monitor
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8.
HighCVSS 8.8No exploitEPSS 3%libssh · libsshDec 10, 2019
- CVE-2026-5985135Monitor
Libssh: libssh: authentication bypass via missing gssapi principal check
HighCVSS 8.8No exploitEPSS 0%libssh · libsshJul 21, 2026
- CVE-2025-537235Monitor
Libssh: incorrect return code handling in ssh_kdf() in libssh
HighCVSS 8.8No exploitEPSS 0%libssh · libsshJul 4, 2025
- CVE-2012-456234Monitor
Multiple integer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (infinite loop or crash) and possibly
HighCVSS 7.5No exploitEPSS 13%libssh · libsshNov 30, 2012
- CVE-2012-456032Monitor
Multiple buffer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary c
HighCVSS 7.5No exploitEPSS 6%libssh · libsshNov 30, 2012
- CVE-2025-598732Monitor
Libssh: invalid return code for chacha20 poly1305 with openssl backend
HighCVSS 8.1No exploitEPSS 2%libssh · libsshJul 7, 2025
- CVE-2026-096632Monitor
Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()
HighCVSS 8.2No exploitEPSS 1%libssh · libsshMar 26, 2026
- CVE-2015-314631Monitor
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, w
HighCVSS 7.5No exploitEPSS 4%libssh · libsshApr 13, 2016
- CVE-2012-606331Monitor
Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (
HighCVSS 7.5No exploitEPSS 4%libssh · libsshNov 30, 2012
- CVE-2026-5985030Monitor
Libssh: libssh: use-after-free via data callbacks on closed channels
HighCVSS 7.5No exploitEPSS 1%libssh · libsshJul 21, 2026
- CVE-2026-5984730Monitor
Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
HighCVSS 7.5No exploitEPSS 1%libssh · libsshJul 21, 2026
- CVE-2026-5984930Monitor
Libssh: libssh: denial of service via automatic certificate authentication loop
HighCVSS 7.5No exploitEPSS 0%libssh · libsshJul 21, 2026
- CVE-2012-455929Monitor
Multiple double free vulnerabilities in the (1) agent_sign_data function in agent.c, (2) channel_request function in channels.c, (3) ssh_use
MediumCVSS 6.8No exploitEPSS 5%libssh · libsshNov 30, 2012
- CVE-2026-1537029Monitor
Libssh: libssh: stack buffer overflow in sftp server longname construction
HighCVSS 7.3No exploitEPSS 0%libssh · libsshJul 21, 2026
- CVE-2025-1482128Monitor
Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows
HighCVSS 7.0No exploitEPSS 0%libssh · libsshApr 7, 2026
- CVE-2021-363427Monitor
A flaw has been found in libssh in versions prior to 0.9.6.
MediumCVSS 6.5No exploitEPSS 5%libssh · libsshAug 31, 2021
- CVE-2026-373127Monitor
libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds
MediumCVSS 6.9No exploitEPSS 1%libssh · libsshMar 8, 2026
- CVE-2023-166726Monitor
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing.
MediumCVSS 6.5No exploitEPSS 1%libssh · libsshMay 26, 2023
- CVE-2023-228326Monitor
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signatur
MediumCVSS 6.5No exploitEPSS 1%libssh · libsshMay 26, 2023
- CVE-2023-360326Monitor
Processing sftp server read may cause null dereference
MediumCVSS 6.5No exploitEPSS 1%libssh · libsshJul 21, 2023
- CVE-2025-544926Monitor
Libssh: integer overflow in libssh sftp server packet length validation leading to denial of service
MediumCVSS 6.5No exploitEPSS 1%libssh · libsshJul 25, 2025
- CVE-2026-5984326Monitor
Libssh: libssh: denial of service via zero advertised channel packet size
MediumCVSS 6.5No exploitEPSS 1%libssh · libsshJul 21, 2026
- CVE-2026-5984426Monitor
Libssh: libssh: denial of service via oversized sftp read length
MediumCVSS 6.5No exploitEPSS 1%libssh · libsshJul 21, 2026