Tag
high
advisory
CVE-2026-66032 - libssh2 SFTP Double-Free Vulnerability
4 TTPs 4 CVEsA double-free vulnerability, CVE-2026-66032, in libssh2 versions through 1.11.1 allows a malicious SSH server to corrupt the heap of an authenticated client opening an SFTP session, potentially leading to arbitrary code execution.
libssh2 <= 1.11.1
ssh
sftp
double-free
vulnerability
libssh2
memory-corruption
rce
DoS
+2
4t
4c
medium
advisory
libssh2 Integer Overflow Vulnerability (CVE-2026-7598)
2 rules 1 TTP 1 CVEAn integer overflow vulnerability exists in libssh2 versions up to 1.11.1 within the userauth_password function of src/userauth.c, which can be triggered remotely by manipulating username_len/password_len arguments.
libssh2 <= 1.11.1
cve
integer_overflow
libssh2
2r
1t
1c