CVE-2026-59847Medium· 5.9▾ SunlitA flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
libssh >= 0.9.0, < 0.11.5libssh = 0.12.0hardened_imagesenterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0Upgrade past the affected range:
libssh 0.11.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59842Low· 3.7A flaw was found in libssh
CVE-2026-59849Low· 3.1A flaw was found in libssh
CVE-2026-15370Medium· 6.7A flaw was found in libssh
CVE-2026-0968Low· 3.1A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation
CVE-2026-0967Medium· 5.5A flaw was found in libssh
CVE-2026-0965Low· 3.3A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing