CVE-2025-15661Disclosure(libssh2 / libssh2)

MEDIUMCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch libssh2 libssh2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libssh2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 1 mentions (2026-06-18); latest day: 1
  • 7 total mentions across 7 days

Affected systems

Vendors
Products
libssh2

Deep dive

Activity timeline7 mentions / 7d
00111Mentions · 2026-06-18: 1Mentions · 2026-06-25: 1Mentions · 2026-06-30: 1Mentions · 2026-07-08: 1Mentions · 2026-07-14: 1Mentions · 2026-07-20: 1Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-06-25: 1Exploit Tool / Code · 2026-06-25: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-20: 1Patch / Workaround · 2026-08-19: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-25: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-20: 1Technical Details · 2026-08-19: 106-1806-2506-3007-0807-1407-2008-19
Signal classification4 categories
Disclosure
228.6%
Patch
228.6%
General
228.6%
PoC
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-181
Disclosure1
2026-06-251
PoC1
2026-06-301
Patch1
2026-07-081
General1
2026-07-141
General1
2026-07-201
Disclosure1
2026-08-191
Patch1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    PoC

    libssh2: CVE-2026-55200 (critical), CVE-2025-15661 (high), CVE-2026-55199 (high) https://www.openwall.com/lists/oss-security/2026/06/23/10 libssh2 CVE-2026-55200 PoC and local RCE scaffold https://www.openwall.com/lists/oss-security/2026/06/23/11

    Post summary

    The provided messages disclose three libssh2 CVEs and include a Proof of Concept plus local RCE scaffold for CVE‑2026‑55200, indicating exploit code is available but no evidence of active exploitation.

    020721.1K
    4.7K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SSH ❗ CVE-2026-55200 ❗ CVE-2026-55199 ❗ CVE-2025-15661 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-ssh/ https://t.co/9p3ghUfVJj

    Post summary

    The message lists three SSH product CVEs and directs readers to an external CERT advisory for additional information, but provides no further details in the snippet.

    01001292
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15661 Out-of-Bounds Heap Read in libssh2 Through 1.11.1 SFTP Symlink Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15661

    Post summary

    The post points to CVE‑2025‑15661, describing an out‑of‑bounds heap read vulnerability in libssh2, but provides no PoC, exploit code, or mitigation details.

    0101086
    4.1K followersView on X
  • Stanislav Klevtsov@stansecure
    Patch

    Top #CVE to #patch this week👀 - @Microsoft #PatchTuesday, Aug 2026: Exchange, Office, PowerShell, VS Code, and other software multiple vulns - @Adobe #ColdFusion multiple vulns (CVE-2026-11897) - @ApacheOfbiz Improper Auth (CVE-2025-15661) - #CheckPoint SmartConsole Auth Bypass (CVE-2026-56001) - @Cisco ASA Remote Access SSL VPN DoS (CVE-2026-41989) - @SAP Commerce Cloud unauth RCE (CVE-2026-58231) - @Apple macOS Screen Sharing exploit (CVE-2026-65400) - @FlowiseAI #RCE (CVE-2026-14130)

    Post summary

    The post enumerates multiple CVEs across vendors with brief vulnerability notes, emphasizing the urgency of applying patches within the upcoming PatchTuesday cycle.

    1000091
    44 followersView on X
  • VulniPulse@vulnipulse
    Disclosure

    ⚠️ NetApp Active IQ Unified Manager for VMware vSphere alert: CVE-2025-15661 (CVSS 8.3) Attackers could disrupt service or cause a denial of service. No workaround is available; follow the vendor advisory for updates. https://vulnipulse.com/advisories/netapp-ntap-20260703-0019 #NetApp #CyberSecurity #CVE

    Post summary

    NetApp alerts on CVE‑2025‑15661, a high‑severity denial‑of‑service flaw in Active IQ Unified Manager for VMware vSphere, urging users to follow the vendor advisory as no workaround exists.

    0000031
    6 followersView on X
  • Windows Forum@windowsforum
    General

    🪟 Another “not a Windows bug” CVE that still crashes the party: libssh2 SFTP symlink overread lets a sketchy SSH server leak memory. Supply chain automation: great… until it scales the mess. https://windowsforum.com/threads/cve-2025-15661-libssh2-sftp-heap-overread-supply-chain-automation-risk.435814/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #SupplyChain #CveMitigation #Libssh2 #SftpSecurity https://t.co/67GGeghbmy

    Post summary

    The tweet highlights a CVE-2025-15661 involving a libssh2 SFTP heap overread that leaks memory, but it does not provide a PoC, exploit, patch, or claim of active exploitation.

    0000052
    1.2K followersView on X
  • CyberTLDR@CyberTLDR
    Patch

    3/3 No release yet but patch commit 97acf3d is in mainline. Debian is backporting it. Inventory static libssh2 copies package managers miss. Restrict outbound SSH to trusted hosts. Also patch CVE-2026-55199 (8.2) and CVE-2025-15661 (8.3). #patchnow #SSH #cybersecurity

    Post summary

    The post announces a new patch commit in the mainline and its Debian backport, confirming updates for SSH related CVE-2026-55199 and CVE-2025-15661.

    0000044
    16 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibssh2libssh2---

Explore more