Threat Advisory

libssh2 Flaws Let Rogue SSH Servers Corrupt Client Heap Memory

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting libssh2 versions All four bugs affect libssh2 through version 1 have been identified in libssh2 through version 1.11.1, which could allow a malicious SSH server to corrupt heap memory in SSH and SFTP clients. The overall risk/impact is high due to the potential for double-free heap corruption and other memory-related issues.

CVE-2026-66032 (CVSS 8.8 — High): CVE-2026-66032 triggers a double-free of an SFTP buffer, which can lead to heap corruption. An attacker can exploit this vulnerability by connecting to a malicious SSH server that sends a specially crafted packet.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting libssh2 versions All four bugs affect libssh2 through version 1 have been identified in libssh2 through version 1.11.1, which could allow a malicious SSH server to corrupt heap memory in SSH and SFTP clients. The overall risk/impact is high due to the potential for double-free heap corruption and other memory-related issues.

CVE-2026-66032 (CVSS 8.8 — High): CVE-2026-66032 triggers a double-free of an SFTP buffer, which can lead to heap corruption. An attacker can exploit this vulnerability by connecting to a malicious SSH server that sends a specially crafted packet.[emaillocker id="1283"]

CVE-2026-66033 (CVSS 7.5 — Moderate): CVE-2026-66033 underflows a size calculation during AES-GCM setup, causing the client to crash. An attacker can exploit this vulnerability by sending a short packet to an SFTP client.

CVE-2026-66034 (CVSS 7.5 — Moderate): CVE-2026-66034 reads past a public-key buffer and frees an uninitialized pointer, exposing heap addresses and undermining ASLR.

CVE-2026-66035 (CVSS 8.8 — High): CVE-2026-66035 triggers a heap overflow during Encrypt-then-MAC negotiation, allowing an attacker to corrupt the client's memory. These vulnerabilities collectively present a significant risk to SSH and SFTP clients that connect to malicious SSH servers. Administrators should update their libssh2 installations to a version beyond 1.11.1 or apply the upstream commits directly. These vulnerabilities collectively present a significant risk to SSH and SFTP clients that connect to malicious SSH servers.

These vulnerabilities collectively present a significant risk to SSH and SFTP clients that connect to malicious SSH servers.

RECOMMENDATION:

We recommend you to update libssh2 to version 5e4776146552d898b9c0e1b313cd093fa8dc92d0 or 1.11.1.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu