CVE-2026-59849Low· 3.1▾ SunlitA flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denia…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.
libssh >= 0.11.0, < 0.11.5libssh = 0.12.0hardened_imagesenterprise_linux = 10.0enterprise_linux = 10.2enterprise_linux_for_els = 10.2enterprise_linux_for_eus = 10.2enterprise_linux_for_ibm_z_systems = 10.0enterprise_linux_for_ibm_z_systems = 10.2enterprise_linux_for_ibm_z_systems_els = 10.2enterprise_linux_for_ibm_z_systems_eus = 10.2enterprise_linux_for_power_little_endian = 10.0enterprise_linux_for_power_little_endian = 10.2enterprise_linux_for_power_little_endian_els = 10.2enterprise_linux_for_power_little_endian_eus = 10.2Upgrade past the affected range:
libssh 0.11.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59842Low· 3.7A flaw was found in libssh
CVE-2026-59847Medium· 5.9A flaw was found in libssh
CVE-2026-15370Medium· 6.7A flaw was found in libssh
CVE-2026-0968Low· 3.1A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation
CVE-2026-0967Medium· 5.5A flaw was found in libssh
CVE-2026-0965Low· 3.3A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing