Threats Tagged 'cve-2026-66035'
View all threats tagged with 'cve-2026-66035'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-66035'
Click on any threat for detailed analysis and mitigation recommendations
0 This update for libssh2_org fixes the following issues: - CVE-2025-15661: out-of-bounds heap read vulnerability in the `sftp_symlink()` function in `src/sftp.c` (bsc#1268546). - CVE-2026-7598: integer overflow in function `userauth_password` of file `src/userauth.c` (bsc#1263890). - CVE-2026-58050: heap buffer overflow due to missing bounds check in attribute count of publickey-subsystem response (bsc#1269568). - CVE-2026-58051: uninitialized pointer freed when malformed responses are sent by an SSH server (bsc#1269567). - CVE-2026-66032: arbitrary code execution via double-free in SFTP session (bsc#1272737). - CVE-2026-66033: denial of service via integer underflow in AES-GCM cipher negotiation (bsc#1272736). - CVE-2026-66034: information disclosure and potential arbitrary code execution via heap out-of-bounds read (bsc#1272735). - CVE-2026-66035: arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734). Join the discussion | GCVE Database | 08/10/2026, 15:24:32 UTC Added: 07/03/2026, 22:50:39 UTC |
0 These are all security issues fixed in the libssh2-1-1.11.1-4.1 package on the GA media of openSUSE Tumbleweed. Join the discussion | GCVE Database | 08/05/2026, 00:00:00 UTC Added: 06/29/2026, 22:11:11 UTC |
A heap buffer overflow vulnerability (CVE-2026-66035) exists in libssh2, affecting Red Hat Hardened Images RPMs. A malicious SSH server can exploit this flaw during the Encrypt-then-MAC cipher negotiation to corrupt heap memory on the client side before authentication. This may lead to arbitrary code execution on the client. Exploitation requires the client to connect to a malicious server, limiting the attack surface. Red Hat has issued an advisory describing the issue and recommending restricting SSH client connections to trusted servers. No official fix has been released yet for the affected Red Hat Hardened Images packages. Join the discussion | GCVE Database | 07/27/2026, 19:37:50 UTC Added: 08/02/2026, 21:27:09 UTC |
Showing 1 to 3 of 3 results