CVE-2026-0968
published 2026-03-26CVE-2026-0968: A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an…
PriorityP411low3.1CVSS 3.1
AVNACHPRNUIRSUCNINAL
EPSS
0.44%
35.8th percentile
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libssh | < libssh 0.12.0-1 (forky) | libssh 0.12.0-1 (forky) |
| libssh | libssh | <= 0.11.3 | — |
| libssh | libssh | >= 0 < 0.12.0-1 | 0.12.0-1 |
| libssh | libssh | >= 0 < 0.9.6-2ubuntu0.22.04.6 | 0.9.6-2ubuntu0.22.04.6 |
| libssh | libssh | >= 0 < 0.10.6-2ubuntu0.3 | 0.10.6-2ubuntu0.3 |
| libssh | libssh | >= 0 < 0.11.2-1ubuntu0.2 | 0.11.2-1ubuntu0.2 |
| libssh | libssh | >= 0 < 0.6.3-4.3ubuntu0.6+esm4 | 0.6.3-4.3ubuntu0.6+esm4 |
| libssh | libssh | >= 0 < 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6 | 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm6 |
| libssh | libssh | >= 0 < 0.9.3-2ubuntu2.5+esm3 | 0.9.3-2ubuntu2.5+esm3 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
osv3.1LOW
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-0968: A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field with
osv·2026-03-26·CVSS 3.1
CVE-2026-0968 [LOW] CVE-2026-0968: A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field with
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
GHSA
GHSA-6w3m-r3qq-cr2h: A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field with
ghsa_unreviewed·2026-03-26
CVE-2026-0968 [LOW] CWE-476 GHSA-6w3m-r3qq-cr2h: A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field with
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
OSV
libssh vulnerabilities
osv·2026-02-23·CVSS 3.1
CVE-2025-8277 [LOW] libssh vulnerabilities
libssh vulnerabilities
USN-8051-1 fixed vulnerabilities in libssh. This update provides the
corresponding updates for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS.
Original advisory details:
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly handled parsing configuration
files. A local attacker could possib
OSV
libssh vulnerabilities
osv·2026-02-18·CVSS 3.1
CVE-2025-8277 [LOW] libssh vulnerabilities
libssh vulnerabilities
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly handled parsing configuration
files. A local attacker could possibly use this issue to cause libssh to
access non-regular files, resulting in a denial of service. (CVE-2026-0965)
It was discovered that libssh incorrectly handled the ssh_get_hexa()
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2026-02-23·CVSS 3.1
CVE-2026-0965 [LOW] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
USN-8051-1 fixed vulnerabilities in libssh. This update provides the
corresponding updates for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS.
Original advisory details:
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly han
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2026-02-18·CVSS 3.1
CVE-2026-0965 [LOW] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
It was discovered that libssh clients incorrectly handled the key exchange
process. A remote attacker could possibly use this issue to cause libssh
clients to crash, resulting in a denial of service. (CVE-2025-8277)
It was discovered that the libssh SCP client incorrectly sanitized paths
received from servers. A remote attacker could use this issue to cause
libssh SCP clients to overwrite files outside of the working directory and
possibly execute arbitrary code. (CVE-2026-0964)
It was discovered that libssh incorrectly handled parsing configuration
files. A local attacker could possibly use this issue to cause libssh to
access non-regular files, resulting in a denial of service. (CVE-2026-0965)
It wa
Red Hat
libssh: libssh: Denial of Service due to malformed SFTP message
vendor_redhat·2026-02-10·CVSS 9.8
CVE-2026-0968 [CRITICAL] CWE-476 libssh: libssh: Denial of Service due to malformed SFTP message
libssh: libssh: Denial of Service due to malformed SFTP message
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a
Debian
CVE-2026-0968: libssh - A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol...
vendor_debian·2026·CVSS 9.8
CVE-2026-0968 [CRITICAL] CVE-2026-0968: libssh - A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol...
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of service (DoS) due to application crashes.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.12.0-1)
sid: resolved (fixed in 0.12.0-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-0968 libssh: libssh: Denial of Service due to malformed SFTP message
bugzilla·2026-02-04·CVSS 3.1
CVE-2026-0968 [LOW] CVE-2026-0968 libssh: libssh: Denial of Service due to malformed SFTP message
CVE-2026-0968 libssh: libssh: Denial of Service due to malformed SFTP message
A malicious SFTP server can send malformed longname field of the
`SSH_FXP_NAME` message (file listing). Due to the missing NULL check,
the libssh could read beyond the buffer bounds on heap, causing
unexpected behavior or crashes.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:18160 https://access.redhat.com/errata/RHSA-2026:18160
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18683 https://access.redhat.com/errata/RHSA-2026:18683
Wiz
CVE-2026-0968 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-0968 [CRITICAL] CVE-2026-0968 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0968 :
NixOS vulnerability analysis and mitigation
SSH_FXP_NAME
Source : NVD
## 9.8
Score
Published March 26, 2026
Severity CRITICAL
CNA Score 3.1
Affected Technologies
NixOS
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libssh
libssh4
Sources
NVD
Chainguard No Fix Added at: Apr 05, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Feb 12, 2026
Debian 14 Severity CRITICAL Has Fix Added at: Feb 12, 2026
Echo Severity CRITICAL No Fix Added at: Feb 12, 2026
Homebrew Severity CRITICAL No Fix Added at: Apr 06, 2026
MinimOS Severity CRITICAL Has Fix Added at: Apr 05, 2026
Nix Seve
2026-03-26
Published