CVE-2026-0965

Source
https://cve.org/CVERecord?id=CVE-2026-0965
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0965.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-0965
Downstream
AZL (1)
BELL (1)
CLSA (1)
DEBIAN (1)
ECHO (1)
JLSEC (1)
MGASA (1)
MINI (1)
OESA (6)
openSUSE (2)
RHSA (2)
RLSA (2)
SUSE (9)
UBUNTU (1)
Related
Published
2026-03-26T20:06:33Z
Modified
2026-09-03T03:30:19Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Libssh: libssh: denial of service via improper configuration file handling
Details

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or large system files, which can disrupt normal operations.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-73"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0965.json"
}
References

Affected packages

Git / gitlab.com/libssh/libssh-mirror

Affected ranges

Type
GIT
Repo
https://gitlab.com/libssh/libssh-mirror
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "0.11.3"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

libssh-0.*
libssh-0.11.0
libssh-0.11.1
libssh-0.11.2
libssh-0.11.3
libssh-0.8.0
Other
release-0-3-0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0965.json"