Vuln Signal Radar
public-safe defensive signal
HIGHpublic-safe

CVE-2026-66034

NVD: libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. NVD: In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from... OSV: libssh2 Heap Out-of-Bounds Read via publickey subsystem

CVSS
7.7
Severity
HIGH
EPSS
0.0025 (17)
KEV
-

Source-published summary

NVD: libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. NVD: In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from... OSV: libssh2 Heap Out-of-Bounds Read via publickey subsystem

Possible impact

This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.

Affected context

vendor/product: libssh2 / libssh2

Remediation / advisory

Patch confirmed by source text; fixed version context: commit.

Why it matters

This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.; CVSS 7.7 (HIGH); EPSS percentile 17; not listed in KEV; Patch confirmed by source text; fixed version context: commit; sources: NVD, OSV.

What to verify

Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.

Exposure hint

exposure unknown

Impact tags

明示タグなし

Urgency reasons

CVSS HIGHaffected product presentvendor advisory presentrecent updateremediation reference present

Source-derived note

Summary derived from NVD / OSV description; unsafe procedural detail is not shown.

Redaction metadata

source summary used
True
fallback summary used
False
unsafe procedural detail present
false
raw source displayed
false
public summary redacted
true

Remediation handoff

Public-safe static handoff for human/Codex remediation planning. Scan, patch, external execution, and auto remediation are disabled.

Safety note

This radar shows source-published defensive context only. Exploit procedures, exploit strings, scanner commands, and auto-remediation are not provided.

Official references