securityonline.info 7/28/2026, 4:01:39 AM · external

Serious libssh2 flaws let rogue SSH servers corrupt client memory

Serious libssh2 flaws let rogue SSH servers corrupt client memory
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source github.com

FOUR new vulnerabilities in libssh2 threaten SSH and SFTP clients, allowing malicious servers to corrupt memory. Disclosed on July 24, 2026, these flaws carry a high severity rating of up to 8.8 on the CVSS scale. Key vulnerabilities include double-free heap corruption and integer underflow. While no exploitation has been confirmed, patches are available. Users are advised to update to specific commits to mitigate risks, and to connect only to trusted SSH servers until updated.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline