libssh
23 known vulnerabilities affecting libssh products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-5987 | Medium | 1.5% | 8.1 | A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL libra… | |
| CVE-2026-0966 | Medium | 0.6% | 8.2 | A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a… | |
| CVE-2026-59851 | Medium | 0.3% | 8.8 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssap… | |
| CVE-2025-14821 | Medium | 0.1% | 7.8 | A flaw was found in libssh. This vulnerability allows local man-in-the-middle at… | |
| CVE-2025-5318 | Low | 1.7% | 5.4 | A flaw was found in the libssh library in versions less than 0.11.2. An out-of-b… | |
| CVE-2025-5449 | Low | 0.8% | 6.5 | A flaw was found in the SFTP server message decoding logic of libssh. The issue … | |
| CVE-2026-59843 | Low | 0.6% | 6.5 | A flaw was found in libssh. A remote authenticated peer can advertise a zero max… | |
| CVE-2026-59844 | Low | 0.6% | 6.5 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ… | |
| CVE-2025-5351 | Low | 0.5% | 6.5 | A flaw was found in the key export functionality of libssh. The issue occurs in … | |
| CVE-2026-0968 | Low | 0.4% | 3.1 | A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol… | |
| CVE-2025-5372 | Low | 0.4% | 5.0 | A flaw was found in libssh versions built with OpenSSL versions older than 3.0, … | |
| CVE-2026-0964 | Low | 0.4% | 6.3 | A malicious SCP server can send unexpected paths that could make the client appl… | |
| CVE-2026-59842 | Low | 0.4% | 3.7 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-sup… | |
| CVE-2026-59850 | Low | 0.3% | 4.3 | A flaw was found in libssh. If data packets are processed after a channel is clo… | |
| CVE-2026-59848 | Low | 0.3% | 5.3 | A flaw was found in libssh. A malicious SFTP server can send responses for unkno… | |
| CVE-2026-59847 | Low | 0.3% | 5.9 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds usin… | |
| CVE-2026-59849 | Low | 0.2% | 3.1 | A flaw was found in libssh. Logic errors in automatic certificate-based public k… | |
| CVE-2026-0967 | Low | 0.2% | 5.5 | A flaw was found in libssh. A remote attacker, by controlling client configurati… | |
| CVE-2025-8114 | Low | 0.2% | 4.7 | A flaw was found in libssh, a library that implements the SSH protocol. When cal… | |
| CVE-2026-0965 | Low | 0.2% | 3.3 | A flaw was found in libssh where it can attempt to open arbitrary files during c… | |
| CVE-2026-15370 | Low | 0.2% | 6.7 | A flaw was found in libssh. During SFTP server directory listing, the longname f… | |
| CVE-2026-59846 | Low | 0.1% | 3.9 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCom… | |
| CVE-2026-59845 | Low | 0.1% | 5.3 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failu… |