cbcvebase.
CVE-2026-0966
published 2026-03-26

CVE-2026-0966: A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited…

PriorityP347high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.58%
43.9th percentile
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlibssh< libssh 0.12.0-1 (forky)libssh 0.12.0-1 (forky)
libsshlibssh< 0.11.40.11.4
libsshlibssh>= 0 < 0.12.0-10.12.0-1
libsshlibssh>= 0 < 0.9.6-2ubuntu0.22.04.60.9.6-2ubuntu0.22.04.6
libsshlibssh>= 0 < 0.10.6-2ubuntu0.30.10.6-2ubuntu0.3
libsshlibssh>= 0 < 0.11.2-1ubuntu0.20.11.2-1ubuntu0.2
libsshlibssh>= 0 < 0.6.3-4.3ubuntu0.6+esm40.6.3-4.3ubuntu0.6+esm4
libsshlibssh>= 0 < 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm60.8.0~20170825.94fa1e38-1ubuntu0.7+esm6
libsshlibssh>= 0 < 0.9.3-2ubuntu2.5+esm30.9.3-2ubuntu2.5+esm3
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatopenshift_container_platform

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.