CVE-2026-66033
NVD: libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM... NVD: Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any... OSV: libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
8.7 Severity
HIGH EPSS
0.0037 (30) KEV
-
Source-published summary
NVD: libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM... NVD: Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any... OSV: libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
Possible impact
Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.
Affected context
vendor/product: libssh2 / libssh2
Remediation / advisory
Patch confirmed by source text; fixed version context: commit.
Why it matters
Source describes service availability risk. Possible impact: The affected service may become unavailable or unreliable.; CVSS 8.7 (HIGH); EPSS percentile 30; not listed in KEV; Patch confirmed by source text; fixed version context: commit; sources: NVD, OSV.
What to verify
Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.
Exposure hint
exposure unknown
Impact tags
Urgency reasons
Source-derived note
Summary derived from NVD / OSV description; unsafe procedural detail is not shown.
Redaction metadata
- source summary used
- True
- fallback summary used
- False
- unsafe procedural detail present
- false
- raw source displayed
- false
- public summary redacted
- true
Remediation handoff
Public-safe static handoff for human/Codex remediation planning. Scan, patch, external execution, and auto remediation are disabled.
Safety note
This radar shows source-published defensive context only. Exploit procedures, exploit strings, scanner commands, and auto-remediation are not provided.
Official references
- https://nvd.nist.gov/vuln/detail/CVE-2026-66033
- https://osv.dev/vulnerability/CVE-2026-66033
- https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6
- https://github.com/libssh2/libssh2/pull/2401
- https://www.vulncheck.com/advisories/libssh2-integer-underflow-dos-via-aes-gcm-cipher-negotiation