A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauthpassword of the file src/userauth.c. Such manipulation of the argument usernamelen/passwordlen leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.
Last updated 13 July 2026
Last updated 4 September 2026
libssh2 Heap Out-of-Bounds Read via publickey subsystem
Last updated 4 September 2026
Last updated 13 July 2026
libssh2 Heap Buffer Overflow via ETM Cipher Negotiation
Last updated 30 June 2026
Last updated 30 June 2026
Last updated 30 June 2026