A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.
References
| Link | Resource |
|---|---|
| https://github.com/libssh2/libssh2/ | Product |
| https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1 | Patch |
| https://github.com/libssh2/libssh2/pull/1858 | Issue Tracking |
| https://vuldb.com/submit/805564 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/360555 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/360555/cti | Permissions Required VDB Entry |
| https://access.redhat.com/errata/RHSA-2026:16736 | |
| https://access.redhat.com/errata/RHSA-2026:7021 | |
| https://access.redhat.com/security/cve/CVE-2026-7598 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464597 | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7598.json | |
| https://vuldb.com/submit/805564 | Third Party Advisory VDB Entry |
Configurations
History
30 Jun 2026, 03:21
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
07 May 2026, 01:47
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:* | |
| References | () https://github.com/libssh2/libssh2/ - Product | |
| References | () https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1 - Patch | |
| References | () https://github.com/libssh2/libssh2/pull/1858 - Issue Tracking | |
| References | () https://vuldb.com/submit/805564 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/360555 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/360555/cti - Permissions Required, VDB Entry | |
| First Time |
Libssh2 libssh2
Libssh2 |
04 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://vuldb.com/submit/805564 - |
01 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-01 22:16
Updated : 2026-07-15 01:17
NVD link : CVE-2026-7598
Mitre link : CVE-2026-7598
CVE.ORG link : CVE-2026-7598
JSON object : View
Products Affected
libssh2
- libssh2
