CVE Tools

Libssh2

2 CVEs tracked since 2015. Since Mar 2015, none of them reached CISA KEV.

Libssh2 CVEs per month

Mar 2015 to Apr 2016. Point at a month, or focus the strip and use the arrow keys.
Libssh2 CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0310
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-0410

Products

The products that kept showing up in Libssh2's monthly top three, with their CVEs summed over those months.

  1. Libssh222 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Libssh2.

  1. CVE-2026-66035libssh2 Heap Buffer Overflow via ETM Cipher Negotiation7.5
  2. CVE-2026-66034libssh2 Heap Out-of-Bounds Read via publickey subsystem7.5
  3. CVE-2026-66033libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation7.5
  4. CVE-2026-66032libssh2 Double-Free Heap Corruption via sftp_open()8.8
  5. CVE-2026-58051libssh2 - Free of Uninitialized Pointer in publickey List Cleanup6.5
  6. CVE-2026-58050libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation7.0
  7. CVE-2025-15661libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c6.5
  8. CVE-2026-55200libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c8.1
  9. CVE-2026-55199libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler5.9
  10. CVE-2026-7598libssh2 userauth.c userauth_password integer overflow7.3
  11. CVE-2023-48795The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (fr...5.9
  12. CVE-2020-22218An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.7.5
  13. CVE-2019-17498In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a...8.1
  14. CVE-2019-13115In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the ...8.1
  15. CVE-2019-3856An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH ...8.8

The record

Peak rank
#102 in Mar 2015
Busiest month shown
Mar 2015, 1 CVEs
Months with a KEV entry
0 since Mar 2015
Monthly snapshots
2 since 2015
Libssh2's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store