CVE-2026-59842Low· 3.7▾ SunlitA flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could al…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.
libssh = 0.12.0hardened_imagesenterprise_linux = 10.0enterprise_linux = 10.2enterprise_linux_for_els = 10.2enterprise_linux_for_eus = 10.2enterprise_linux_for_ibm_z_systems = 10.0enterprise_linux_for_ibm_z_systems = 10.2enterprise_linux_for_ibm_z_systems_els = 10.2enterprise_linux_for_ibm_z_systems_eus = 10.2enterprise_linux_for_power_little_endian = 10.0enterprise_linux_for_power_little_endian = 10.2enterprise_linux_for_power_little_endian_els = 10.2enterprise_linux_for_power_little_endian_eus = 10.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59849Low· 3.1A flaw was found in libssh
CVE-2026-59847Medium· 5.9A flaw was found in libssh
CVE-2026-15370Medium· 6.7A flaw was found in libssh
CVE-2026-0968Low· 3.1A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation
CVE-2026-0967Medium· 5.5A flaw was found in libssh
CVE-2026-0965Low· 3.3A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing