CVE-2026-3731Disclosure(libssh / libssh)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch libssh libssh systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libssh

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-08); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
libssh

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-08: 4Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-08: 4Technical Details · 2026-03-10: 103-0803-1003-11
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-084
Disclosure3General1
2026-03-101
Patch1
2026-03-111
Patch1
Full discourse6 posts
  • Determinate Systems@DeterminateSys
    Patch

    CVE-2026-3731 is now fixed in Determinate Secure Packages, both standard and FIPS variants.

    Post summary

    CVE-2026-3731 has been fixed in Determinate Secure Packages, both standard and FIPS variants.

    040921.1K
    2.7K followersView on X
  • Graham Christensen@grhmc
    Patch

    About to ship a fix for the critical (9.8) CVE-2026-3731 in libssh, in @DeterminateSys secure packages. ref: https://nvd.nist.gov/vuln/detail/CVE-2026-3731

    Post summary

    The announcement focuses on an upcoming patch for the critical CVE-2026-3731 vulnerability in libssh, specifying its high CVSS score.

    001211.5K
    5.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3731 Out-of-Bounds Read Vulnerability in libssh SFTP Extension Name Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3731 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The snippet identifies CVE-2026-3731 as an out-of-bounds read vulnerability in libssh, linking to details and a notification, but provides no PoC, exploit code, patch, or exploitation evidence.

    0001158
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3731 A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of … https://www.cve.org/CVERecord?id=CVE-2026-3731

    Post summary

    CVE-2026-3731 was disclosed as a weakness in libssh 0.11.3 involving SFTP extension handling, with function-level details provided but no PoC, exploit, patch, or active exploitation noted.

    0000097
    56.6K followersView on X
  • S.Komichevsen Matsuk@w4yh
    General

    スコア5.3なら慌てる必要はないかな.. // CVE Record: CVE-2026-3731 "libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds" https://www.cve.org/CVERecord?id=CVE-2026-3731

    Post summary

    The text only notes a CVSS score of 5.3 for CVE-2026-3731 and provides a link to the CVE record, with minimal technical detail and no evidence of exploitation or mitigation.

    0000059
    325 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3731 - libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds Intel Report: https://ift.tt/NwkLn8c

    Post summary

    An alert announces CVE‑2026‑3731, an out‑of‑bounds bug in libssh’s SFTP extension, but provides no exploitation details, patches, or evidence of active attacks.

    0000030
    347 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibsshlibssh---

Explore more