libssh2 vulnerabilities
CVEs whose affected-version data names the libssh2 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55200High· 8.1PoClibssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessiv…
▾ Midnightlibssh2 · libssh2EPSS 4.0%via NVD
CVE-2026-7598High· 7.3A security vulnerability has been detected in libssh2 up to 1.11.1
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow.…
▾ Twilightlibssh2 · libssh2EPSS 0.47%via NVD