CVE-2026-7598

EUVD-2026-26722
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Affected Products (NVD)
VendorProductVersion
libssh2libssh2
𝑥
≤ 1.11.1
𝑥
= Vulnerable software versions
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libssh2
Amazon Linux 2
0:1.4.3-12.amzn2.2.7
fixed
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.4
fixed
libssh2-debuginfo
Amazon Linux 2
0:1.4.3-12.amzn2.2.7
fixed
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.4
fixed
libssh2-debugsource
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.4
fixed
libssh2-devel
Amazon Linux 2
0:1.4.3-12.amzn2.2.7
fixed
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.4
fixed
libssh2-docs
Amazon Linux 2
0:1.4.3-12.amzn2.2.7
fixed
Amazon Linux 2023
0:1.10.0-1.amzn2023.0.4
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
libssh2
Azure Linux 3.0
0:1.11.1-2.azl3
fixed
Common Weakness Enumeration