GHSA-qp28-hpg5-j7xcMediumCVSS 6.5

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an...

Published
July 21, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

🔗 References (4)