VYPR

Libssh2

by Libssh2

Source repositories

CVEs (2)

  • CVE-2026-7598HigMay 1, 2026
    risk 0.40cvss 7.3epss 0.00

    A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.

  • CVE-2016-0787MedApr 13, 2016
    risk 0.39cvss 5.9epss 0.03

    The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."