Libssh is a widely embedded SSH protocol library used across a substantial range of server and embedded applications, where its adoption as a dependency creates exposure that extends well beyond the library's direct user base. The vendor's vulnerability disclosure centers on a single product—the libssh library itself—and recurs through weakness classes including NULL-pointer dereferences, improper authentication enforcement, memory-buffer boundary violations, and out-of-bounds reads that reflect the complexity of protocol state management and cryptographic parsing. A moderate share of the vendor's disclosures acquire public exploit code, consistent with the appeal of SSH implementation flaws for reconnaissance and lateral movement in infrastructure. Defenders should maintain awareness of which applications and appliances embed this library and prioritize updates when authentication or memory-safety flaws are disclosed, since remediation typically requires downstream vendors to rebuild and redistribute their products. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libssh over time
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10933CRITICAL A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, r | Oct 17, 2018 | 9.1 | 90 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2012-4562HIGH Multiple integer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (infinite loop or crash) and possibly execute arbitrary code via unspecified v | Nov 30, 2012 | 7.5 | 30 | NO | NO |
CVE-2025-14821HIGH A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host infor | Apr 7, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-0966HIGH A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker | Mar 26, 2026 | 8.2 | 27 | NO | NO |
CVE-2026-3731HIGH A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the componen | Mar 8, 2026 | 7.5 | 27 | NO | NO |
CVE-2025-5318HIGH A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that pe | Jun 24, 2025 | 8.1 | 27 | NO | NO |
CVE-2019-14889HIGH A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which inclu | Dec 10, 2019 | 8.8 | 27 | NO | NO |
CVE-2012-6063HIGH Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary co | Nov 30, 2012 | 7.5 | 26 | NO | NO |
CVE-2012-4560HIGH Multiple buffer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors. | Nov 30, 2012 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libssh.
Media articles that mention a CVE ID that affects a product developed by Libssh — matched by CVE ID, not by vendor name.