Integer Underflow Vulnerability in libssh2 Affects SSH Clients
CVE-2026-66033

8.7HIGH

Key Information:

Vendor

Libssh2

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-66033?

libssh2 versions up to 1.11.1 have a vulnerability in the ssh2_cipher_crypt() function that allows attackers to trigger a denial-of-service condition. The flaw lies in an integer underflow that occurs during cipher negotiation with malicious SSH servers, specifically when utilizing AES-GCM ciphers. This results in an out-of-bounds read and a memcpy operation that can crash any client attempting to connect, even before any authentication takes place. Users are advised to update to the fixed version to mitigate any risks.

Affected Version(s)

libssh2 0 <= 1.11.1

libssh2 0 <= 1.11.1

libssh2 a2ed82d40964bbc0d64cd717aa0a5a892117d2e6

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VladimirEliTokarev
.