42
I Use This!
Very High Activity
Analyzed about 24 hours ago. based on code collected 2 days ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2026-7598 BDSA-2026-9020 Critical May 01, 2026 A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1
CVE-2026-66035 BDSA-2026-24123 High Jul 24, 2026 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1
CVE-2026-66034 BDSA-2026-24122 High Jul 24, 2026 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitra more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1
CVE-2026-66033 BDSA-2026-24121 High Jul 24, 2026 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in s more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1
CVE-2026-66032 BDSA-2026-24120 High Jul 24, 2026 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1
CVE-2026-58051 BDSA-2026-17142 Medium Jun 28, 2026 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse fa more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1
CVE-2026-58050 BDSA-2026-17139 High Jun 28, 2026 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1
CVE-2026-55200 BDSA-2026-15648 High Jun 17, 2026 libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper boun more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1
CVE-2026-55199 BDSA-2026-15647 High Jun 17, 2026 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/p more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1
CVE-2025-15661 BDSA-2025-124323 Medium Jun 18, 2026 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that al more...
1.11.1, 1.11.0, 1.10.0, 1.8.2, 1.8.1, 1.8.0, 1.7.0, 1.6.0, 1.4.3, 1.4.1