Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

libssh2 — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in libssh2, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerability data for libssh2, an open-source client and server library for SSH, categorized by specific weakness types and associated tags. It collects historical security flaws, including memory corruption, protocol implementation errors, and authentication bypasses, covering the period from the library's initial public releases through the most recent patched versions. Readers can use this aggregation to track the vendor's advisory trends over time, understand the prevalence of specific weakness classes within the codebase, or review the complete vulnerability history of the product to assess long-term stability and security posture. The data supports threat modeling and compliance audits by providing a centralized view of disclosed issues without requiring separate lookups across disparate databases.

Vendor: The libssh2 Project

CVE ID Title CVSS Severity Published
CVE-2026-66035 libssh2 Heap Buffer Overflow via ETM Cipher Negotiation CWE-122 7.5 High 2026-07-24
CVE-2026-66034 libssh2 Heap Out-of-Bounds Read via publickey subsystem CWE-125 7.5 High 2026-07-24
CVE-2026-66033 libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation CWE-191 7.5 High 2026-07-24
CVE-2026-66032 libssh2 Double-Free Heap Corruption via sftp_open() CWE-415 8.8 High 2026-07-24
CVE-2026-58051 libssh2 - Free of Uninitialized Pointer in publickey List Cleanup CWE-908 6.5 Medium 2026-06-28
CVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation CWE-190 7.0 High 2026-06-28
CVE-2025-15661 libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c CWE-125 6.5 Medium 2026-06-18
CVE-2026-55200 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c CWE-680 8.1 High 2026-06-17
CVE-2026-55199 libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler CWE-835 5.9 Medium 2026-06-17
CVE-2026-7598 libssh2 userauth.c userauth_password integer overflow CWE-190 7.3 High 2026-05-01
CVE-2019-3856 libssh2 输入验证错误漏洞 CWE-190 8.8 - 2019-03-25
CVE-2019-3857 libssh2 输入验证错误漏洞 CWE-190 8.8 - 2019-03-25
CVE-2019-3860 libssh2 缓冲区错误漏洞 CWE-125 9.1 - 2019-03-25
CVE-2019-3861 libssh2 缓冲区错误漏洞 CWE-125 9.1 - 2019-03-25
CVE-2019-3863 libssh2 缓冲区错误漏洞 CWE-190 8.8 - 2019-03-25
CVE-2019-3858 libssh2 缓冲区错误漏洞 CWE-125 9.1 - 2019-03-21
CVE-2019-3855 libssh2 输入验证错误漏洞 CWE-190 8.8 - 2019-03-21
CVE-2019-3862 libssh2 缓冲区错误漏洞 CWE-130 9.1 - 2019-03-20
CVE-2019-3859 libssh2 缓冲区错误漏洞 CWE-125 9.1 - 2019-03-20

All 19 known CVE vulnerabilities affecting libssh2 with full Chinese analysis, references, and POCs where available.