CVE-2026-0964
published 2026-03-26CVE-2026-0964: A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be…
PriorityP336medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
0.41%
33.1th percentile
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could be misused to create malicious executable or configuration
files and make the user execute them under specific consequences.
This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libssh | < libssh 0.12.0-1 (forky) | libssh 0.12.0-1 (forky) |
| libssh | libssh | < 0.11.4 | 0.11.4 |
| libssh | libssh | >= 0 < 0.12.0-1 | 0.12.0-1 |
| libssh | libssh | >= 0 < 0.9.6-2ubuntu0.22.04.6 | 0.9.6-2ubuntu0.22.04.6 |
| libssh | libssh | >= 0 < 0.10.6-2ubuntu0.3 | 0.10.6-2ubuntu0.3 |
| libssh | libssh | >= 0 < 0.11.2-1ubuntu0.2 | 0.11.2-1ubuntu0.2 |
| libssh | libssh | >= 0 < 0.6.3-4.3ubuntu0.6+esm4 | 0.6.3-4.3ubuntu0.6+esm4 |
| libssh | libssh | >= 0 < 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6 | 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6 |
| libssh | libssh | >= 0 < 0.9.3-2ubuntu2.5+esm3 | 0.9.3-2ubuntu2.5+esm3 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv3.05.0MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libssh Path path traversal (EUVD-2026-16326 / Nessus ID 298575)
vuldb·2026-05-06·CVSS 6.3
CVE-2026-0964 [MEDIUM] libssh Path path traversal (EUVD-2026-16326 / Nessus ID 298575)
A vulnerability, which was classified as critical, has been found in libssh. This issue affects some unknown processing of the component Path Handler. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-0964. The attack is possible to be carried out remotely. No exploit exists.
OSV
CVE-2026-0964: A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory
osv·2026-03-26·CVSS 5.9
CVE-2026-0964 [MEDIUM] CVE-2026-0964: A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
GHSA
GHSA-9p3w-rm2q-9gxc: A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory
ghsa_unreviewed·2026-03-26·CVSS 5.9
CVE-2026-0964 [MEDIUM] CWE-22 GHSA-9p3w-rm2q-9gxc: A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could be misused to create malicious executable or configuration
files and make the user execute them under specific consequences.
This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
OSV
libssh vulnerabilities
osv·2026-02-23·CVSS 3.1
CVE-2025-8277 [LOW] libssh vulnerabilities
libssh vulnerabilities
USN-8051-1 fixed vulnerabilities in libssh. This update provides the
corresponding updates for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS.
Original advisory details:
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly handled parsing configuration
files. A local attacker could possib
OSV
libssh vulnerabilities
osv·2026-02-18·CVSS 3.1
CVE-2025-8277 [LOW] libssh vulnerabilities
libssh vulnerabilities
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly handled parsing configuration
files. A local attacker could possibly use this issue to cause libssh to
access non-regular files, resulting in a denial of service. (CVE-2026-0965)
It was discovered that libssh incorrectly handled the ssh_get_hexa()
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2026-02-23·CVSS 3.1
CVE-2026-0965 [LOW] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
USN-8051-1 fixed vulnerabilities in libssh. This update provides the
corresponding updates for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS.
Original advisory details:
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly han
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2026-02-18·CVSS 3.1
CVE-2026-0965 [LOW] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly handled parsing configuration
files. A local attacker could possibly use this issue to cause libssh to
access non-regular files, resulting in a denial of service. (CVE-2026-0965)
It wa
Red Hat
libssh: Improper sanitation of paths received from SCP servers
vendor_redhat·2026-02-10·CVSS 5.9
CVE-2026-0964 [MEDIUM] CWE-22 libssh: Improper sanitation of paths received from SCP servers
libssh: Improper sanitation of paths received from SCP servers
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could be misused to create malicious executable or configuration
files and make the user execute them under specific consequences.
This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could be misused to create malicious executable or configuration
files and make the user execute them under specific consequences.
This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
Mitigation: Do not use SCP! SCP is deprecated for severa
Debian
CVE-2026-0964: libssh - A malicious SCP server can send unexpected paths that could make the client appl...
vendor_debian·2026·CVSS 5.9
CVE-2026-0964 [MEDIUM] CVE-2026-0964: libssh - A malicious SCP server can send unexpected paths that could make the client appl...
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.12.0-1)
sid: resolved (fixed in 0.12.0-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-0964 libssh: Improper sanitation of paths received from SCP servers
bugzilla·2026-02-04·CVSS 5.9
CVE-2026-0964 [MEDIUM] CVE-2026-0964 libssh: Improper sanitation of paths received from SCP servers
CVE-2026-0964 libssh: Improper sanitation of paths received from SCP servers
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could be misused to create malicious executable or configuration
files and make the user execute them under specific consequences.
This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:18160 https://access.redhat.com/errata/RHSA-2026:18160
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18683 https://access.redhat.com/errata/RHSA-2026:18683
Wiz
CVE-2026-0964 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-0964 [MEDIUM] CVE-2026-0964 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0964 :
Linux Debian vulnerability analysis and mitigation
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could be misused to create malicious executable or configuration
files and make the user execute them under specific consequences.
This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
Source : NVD
## 5
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 5.0
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libssh4
libssh4-32bit
Sources
N
2026-03-26
Published