CVE-2026-0967
published 2026-03-26CVE-2026-0967: A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when…
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.22%
12.8th percentile
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libssh | < libssh 0.12.0-1 (forky) | libssh 0.12.0-1 (forky) |
| libssh | libssh | <= 0.11.3 | — |
| libssh | libssh | >= 0 < 0.12.0-1 | 0.12.0-1 |
| libssh | libssh | >= 0 < 0.9.6-2ubuntu0.22.04.6 | 0.9.6-2ubuntu0.22.04.6 |
| libssh | libssh | >= 0 < 0.10.6-2ubuntu0.3 | 0.10.6-2ubuntu0.3 |
| libssh | libssh | >= 0 < 0.11.2-1ubuntu0.2 | 0.11.2-1ubuntu0.2 |
| libssh | libssh | >= 0 < 0.6.3-4.3ubuntu0.6+esm4 | 0.6.3-4.3ubuntu0.6+esm4 |
| libssh | libssh | >= 0 < 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6 | 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6 |
| libssh | libssh | >= 0 < 0.9.3-2ubuntu2.5+esm3 | 0.9.3-2ubuntu2.5+esm3 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv3.02.2LOWCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2026-02-23·CVSS 3.1
CVE-2026-0965 [LOW] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
USN-8051-1 fixed vulnerabilities in libssh. This update provides the
corresponding updates for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS.
Original advisory details:
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly han
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2026-02-18·CVSS 3.1
CVE-2026-0965 [LOW] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly handled parsing configuration
files. A local attacker could possibly use this issue to cause libssh to
access non-regular files, resulting in a denial of service. (CVE-2026-0965)
It wa
Red Hat
libssh: libssh: Denial of Service via inefficient regular expression processing
vendor_redhat·2026-02-10·CVSS 5.5
CVE-2026-0967 [MEDIUM] CWE-1333 libssh: libssh: Denial of Service via inefficient regular expression processing
libssh: libssh: Denial of Service via inefficient regular expression processing
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
Mit
Debian
CVE-2026-0967: libssh - A flaw was found in libssh. A remote attacker, by controlling client configurati...
vendor_debian·2026·CVSS 5.5
CVE-2026-0967 [MEDIUM] CVE-2026-0967: libssh - A flaw was found in libssh. A remote attacker, by controlling client configurati...
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.12.0-1)
sid: resolved (fixed in 0.12.0-1)
trixie: open
GHSA
GHSA-6jpg-fr24-wpvf: A flaw was found in libssh
ghsa_unreviewed·2026-03-26
CVE-2026-0967 [LOW] CWE-1333 GHSA-6jpg-fr24-wpvf: A flaw was found in libssh
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
OSV
CVE-2026-0967: A flaw was found in libssh
osv·2026-03-26·CVSS 5.5
CVE-2026-0967 [MEDIUM] CVE-2026-0967: A flaw was found in libssh
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
OSV
libssh vulnerabilities
osv·2026-02-23·CVSS 3.1
CVE-2025-8277 [LOW] libssh vulnerabilities
libssh vulnerabilities
USN-8051-1 fixed vulnerabilities in libssh. This update provides the
corresponding updates for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS.
Original advisory details:
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly handled parsing configuration
files. A local attacker could possib
OSV
libssh vulnerabilities
osv·2026-02-18·CVSS 3.1
CVE-2025-8277 [LOW] libssh vulnerabilities
libssh vulnerabilities
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly handled parsing configuration
files. A local attacker could possibly use this issue to cause libssh to
access non-regular files, resulting in a denial of service. (CVE-2026-0965)
It was discovered that libssh incorrectly handled the ssh_get_hexa()
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-0967 libssh: libssh: Denial of Service via inefficient regular expression processing
bugzilla·2026-02-04·CVSS 5.5
CVE-2026-0967 [MEDIUM] CVE-2026-0967 libssh: libssh: Denial of Service via inefficient regular expression processing
CVE-2026-0967 libssh: libssh: Denial of Service via inefficient regular expression processing
The function `match_pattern()` is used to match conditionals in client
configuration files or known hosts against the hostname the client is
connecting to.
When the configuration file or known_hosts file is controlled by the
attacker, connecting to specific hostnames could cause timeouts and
resource exhaustion due to the ineffective backtracking of complex
regular expressions.
The pattern matching was modified to avoid the needless backtracing.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:18160 https://access.redhat.com/errata/RHSA-2026:18160
---
This issue has been addressed in the following products:
Red Hat Enterprise
Wiz
CVE-2026-0967 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-0967 [MEDIUM] CVE-2026-0967 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0967 :
NixOS vulnerability analysis and mitigation
match_pattern()
Source : NVD
## 5.5
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 2.2
Affected Technologies
NixOS
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 24.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libssh-config
libssh-debuginfo
Sources
NVD
Chainguard No Fix Added at: Apr 02, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Feb 12, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Feb 12, 2026
Echo Severity MEDIUM No Fix Added at: Feb 12, 2026
Homebrew Severity MEDIUM No Fix Added at: Apr 05, 2026
MinimOS Severity MEDIUM Has Fix Added at: Apr 05, 2026
2026-03-26
Published