Multiple security vulnerabilities affecting libssh2 versions All four bugs affect libssh2 through version 1 have been identified in libssh2 through version 1.11.1, which could allow a malicious SSH server to corrupt heap memory in SSH and SFTP clients. The overall risk/impact is high due to the potential for double-free heap corruption and other memory-related issues.
CVE-2026-66032 (CVSS 8.8 — High): CVE-2026-66032 triggers a double-free of an SFTP buffer, which can lead to heap corruption. An attacker can exploit this vulnerability by connecting to a malicious SSH server that sends a specially crafted packet.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting libssh2 versions All four bugs affect libssh2 through version 1 have been identified in libssh2 through version 1.11.1, which could allow a malicious SSH server to corrupt heap memory in SSH and SFTP clients. The overall risk/impact is high due to the potential for double-free heap corruption and other memory-related issues.
CVE-2026-66032 (CVSS 8.8 — High): CVE-2026-66032 triggers a double-free of an SFTP buffer, which can lead to heap corruption. An attacker can exploit this vulnerability by connecting to a malicious SSH server that sends a specially crafted packet.[emaillocker id="1283"]
CVE-2026-66033 (CVSS 7.5 — Moderate): CVE-2026-66033 underflows a size calculation during AES-GCM setup, causing the client to crash. An attacker can exploit this vulnerability by sending a short packet to an SFTP client.
CVE-2026-66034 (CVSS 7.5 — Moderate): CVE-2026-66034 reads past a public-key buffer and frees an uninitialized pointer, exposing heap addresses and undermining ASLR.
CVE-2026-66035 (CVSS 8.8 — High): CVE-2026-66035 triggers a heap overflow during Encrypt-then-MAC negotiation, allowing an attacker to corrupt the client's memory. These vulnerabilities collectively present a significant risk to SSH and SFTP clients that connect to malicious SSH servers. Administrators should update their libssh2 installations to a version beyond 1.11.1 or apply the upstream commits directly. These vulnerabilities collectively present a significant risk to SSH and SFTP clients that connect to malicious SSH servers.
These vulnerabilities collectively present a significant risk to SSH and SFTP clients that connect to malicious SSH servers.
We recommend you to update libssh2 to version 5e4776146552d898b9c0e1b313cd093fa8dc92d0 or 1.11.1.
The following reports contain further technical details:
[/emaillocker]