cvedb.io
CVE-2026-15370
MEDIUM · CVSS 6.7
EPSS exploitation probability: 0%
Published 2026-07-21T09:16:53.683 · Last modified 2026-07-21T09:16:53.683

Summary

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.