CVE-2026-0966

Source
https://cve.org/CVERecord?id=CVE-2026-0966
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0966.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-0966
Downstream
AZL (1)
BELL (1)
CLSA (8)
DEBIAN (1)
ECHO (1)
JLSEC (1)
MGASA (1)
MINI (1)
OESA (6)
openSUSE (2)
RHSA (3)
RLSA (2)
SUSE (9)
UBUNTU (1)
Related
Published
2026-03-26T20:06:28Z
Modified
2026-09-03T03:30:17Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()
Details

A flaw was found in libssh. The API function ssh_get_hexa() is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to SSH_LOG_PACKET (3) or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-124"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0966.json"
}
References

Affected packages

Git / gitlab.com/libssh/libssh-mirror

Affected ranges

Type
GIT
Repo
https://gitlab.com/libssh/libssh-mirror
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.11.4"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

libssh-0.*
libssh-0.11.0
libssh-0.11.1
libssh-0.11.2
libssh-0.11.3
libssh-0.8.0
Other
release-0-3-0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0966.json"