cvedb.io
CVE-2026-0966
HIGH · CVSS 8.2
EPSS exploitation probability: 0%
Published 2026-03-26T21:17:00.783 · Last modified 2026-06-17T10:11:42.263

Summary

A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.

Affected products

libssh — libssh

Does this affect you?

Add your gear to cvedb and we'll alert you only when libssh ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.