Libssh2
2 CVEs tracked since 2015. Since Mar 2015, none of them reached CISA KEV.
Libssh2 CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2015-03 | 1 | 0 |
| 2015-04 | null or fewer | |
| 2015-05 | null or fewer | |
| 2015-06 | null or fewer | |
| 2015-07 | null or fewer | |
| 2015-08 | null or fewer | |
| 2015-09 | null or fewer | |
| 2015-10 | null or fewer | |
| 2015-11 | null or fewer | |
| 2015-12 | null or fewer | |
| 2016-01 | null or fewer | |
| 2016-02 | null or fewer | |
| 2016-03 | null or fewer | |
| 2016-04 | 1 | 0 |
Products
The products that kept showing up in Libssh2's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Libssh2.
- CVE-2026-66035libssh2 Heap Buffer Overflow via ETM Cipher Negotiation7.5
- CVE-2026-66034libssh2 Heap Out-of-Bounds Read via publickey subsystem7.5
- CVE-2026-66033libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation7.5
- CVE-2026-66032libssh2 Double-Free Heap Corruption via sftp_open()8.8
- CVE-2026-58051libssh2 - Free of Uninitialized Pointer in publickey List Cleanup6.5
- CVE-2026-58050libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation7.0
- CVE-2025-15661libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c6.5
- CVE-2026-55200libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c8.1
- CVE-2026-55199libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler5.9
- CVE-2026-7598libssh2 userauth.c userauth_password integer overflow7.3
- CVE-2023-48795The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (fr...5.9
- CVE-2020-22218An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.7.5
- CVE-2019-17498In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a...8.1
- CVE-2019-13115In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the ...8.1
- CVE-2019-3856An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH ...8.8
The record
- Peak rank
- #102 in Mar 2015
- Busiest month shown
- Mar 2015, 1 CVEs
- Months with a KEV entry
- 0 since Mar 2015
- Monthly snapshots
- 2 since 2015