CVE-2026-3731
published 2026-03-08CVE-2026-3731: A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.63%
46.2th percentile
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libssh | < libssh 0.12.0-1 (forky) | libssh 0.12.0-1 (forky) |
| libssh | libssh | <= 0.11.3 | — |
| libssh | libssh | — | — |
| libssh | libssh | — | — |
| libssh | libssh | — | — |
| libssh | libssh | — | — |
| libssh | libssh | >= 0 < 0.12.0-1 | 0.12.0-1 |
| msrc | azl3_libssh_0.10.6-5_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libssh_0.10.6-5_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libssh vulnerability
vendor_ubuntu·2026-03-16
CVE-2026-3731 libssh vulnerability
Title: libssh vulnerability
Summary: libssh could be made to crash or behave unexpectedly.
It was discovered that libssh incorrectly performed bounds checking when
processing SFTP extensions. If a client application queried extension data out
of bounds, it could cause the application to crash, resulting in a denial of
service, or exhibit unintended behavior.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds
vendor_msrc·2026-03-10·CVSS 5.3
CVE-2026-3731 [MEDIUM] CWE-125 libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds
libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds
Mariner: Mariner
VulDB: VulDB
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler
vendor_redhat·2026-03-08·CVSS 6.9
CVE-2026-3731 [MEDIUM] CWE-125 libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler
libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.
A flaw was found in libssh. A remote attacker could trigger an out-of-bounds read vulnerability in the SFTP Extension Name Handler by manipulating the `idx` argument in the `sftp_extensions_get_name`
Debian
CVE-2026-3731: libssh - A weakness has been identified in libssh up to 0.11.3. The impacted element is t...
vendor_debian·2026·CVSS 6.9
CVE-2026-3731 [MEDIUM] CVE-2026-3731: libssh - A weakness has been identified in libssh up to 0.11.3. The impacted element is t...
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.12.0-1)
sid: resolved (fixed in 0.12.0-1)
trixie: open
OSV
CVE-2026-3731: A weakness has been identified in libssh up to 0
osv·2026-03-08·CVSS 6.9
CVE-2026-3731 [MEDIUM] CVE-2026-3731: A weakness has been identified in libssh up to 0
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.
GHSA
GHSA-wg5h-wgv3-pgqh: A weakness has been identified in libssh up to 0
ghsa_unreviewed·2026-03-08
CVE-2026-3731 [MEDIUM] CWE-119 GHSA-wg5h-wgv3-pgqh: A weakness has been identified in libssh up to 0
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-3731 libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler
bugzilla·2026-03-08·CVSS 6.9
CVE-2026-3731 [MEDIUM] CVE-2026-3731 libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler
CVE-2026-3731 libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.
Wiz
CVE-2026-3731 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-3731 [MEDIUM] CVE-2026-3731 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3731 :
NixOS vulnerability analysis and mitigation
A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.
Source : NVD
## 6.9
Score
Published March 8, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
NixOS
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date
https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60https://vuldb.com/?ctiid.349709https://vuldb.com/?id.349709https://vuldb.com/?submit.767120https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xzhttps://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt
2026-03-08
Published