Logo
componentlibssh2
Name
libssh2
Version
1.11.1
Type
library
Description
A client-side C library implementing the SSH2 protocol
Licenses
BSD-3-Clause
PURL
-
CPE
cpe:2.3:*:libssh2:libssh2:1.11.1:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
1.10.0
scarthgap
1.11.1

Patches#


#
Title
Author
Resolve
1
Return error if user KEX methods are invalid #1553 (#1554)
Will Cosgrove <will@panic.com>
2
userauth.c: username_len bounds checking (#1858)
Will Cosgrove <will@panic.com>
CVE-2026-7598

Vulnerabilities#


Name
Analysis
Description
Patched
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.