Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/libssh2/libssh2

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

This update for libssh2_org fixes the following issues: - CVE-2025-15661: out-of-bounds heap read vulnerability in the `sftp_symlink()` function in `src/sftp.c` (bsc#1268546). - CVE-2026-7598: integer overflow in function `userauth_password` of file `src/userauth.c` (bsc#1263890). - CVE-2026-58050: heap buffer overflow due to missing bounds check in attribute count of publickey-subsystem response (bsc#1269568). - CVE-2026-58051: uninitialized pointer freed when malformed responses are sent by an SSH server (bsc#1269567). - CVE-2026-66032: arbitrary code execution via double-free in SFTP session (bsc#1272737). - CVE-2026-66033: denial of service via integer underflow in AES-GCM cipher negotiation (bsc#1272736). - CVE-2026-66034: information disclosure and potential arbitrary code execution via heap out-of-bounds read (bsc#1272735). - CVE-2026-66035: arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734).

Join the discussion
0

These are all security issues fixed in the libssh2-1-1.11.1-4.1 package on the GA media of openSUSE Tumbleweed.

Join the discussion

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Join the discussion

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Join the discussion
0

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/libssh2/libssh2
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses