CVE-2026-58051Patch(libssh2 / libssh2)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch libssh2 libssh2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-908

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libssh2

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-06-28); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
libssh2

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-28: 3Mentions · 2026-06-29: 1Patch / Workaround · 2026-06-28: 2Technical Details · 2026-06-28: 306-2806-29
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-283
Disclosure1Patch2
2026-06-291
General1
Full discourse4 posts
  • VulDB 🛡@vuldb
    General

    Some increased actor activities are shown targeting libssh2 (CVE-2026-58051) https://vuldb.com/vuln/374504/cti

    Post summary

    The post notes that actor activity is reportedly increasing against libssh2 CVE-2026-58051, but no exploit, PoC, or mitigation details are provided.

    00010131
    2.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - libssh2 Multiple Memory Corruption Issues (CVE-2026-58050 & CVE-2026-58051) Two related vulnerabilities in libssh2 through 1.11.1: CVE-2026-58050: Integer overflow in publickey subsystem attribute allocation on 32-bit platforms allows heap buffer overflow. CVE-2026-58051: Uninitialized pointer free in publickey list cleanup after parse failure. A malicious SSH server can trigger both with malformed publickey responses, leading to memory corruption, denial of service, or potentially arbitrary code execution in the client. 👉Affected: libssh2 <= 1.11.1 Action: Upgrade to the latest patched version.

    Post summary

    The post announces two critical memory corruption vulnerabilities in libssh2 and urges users to upgrade to patched versions to mitigate potential denial of service or arbitrary code execution.

    00010108
    232 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-58051 Use-After-Free Vulnerability in libssh2 Through 1.11.1 Public Key Parsing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-58051

    Post summary

    This brief notice announces a Use‑After‑Free flaw in libssh2 (up to v1.11.1) during public key parsing and links to a vulnerability details page.

    00010122
    4.1K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    High CVSS 8.3 CVE-2026-58051 affects libssh2 through 1.11.1. Review dependencies and apply updates. https://nvd.nist.gov/vuln/detail/CVE-2026-58051 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/EojTn7PZQR

    Post summary

    The tweet highlights a high-severity CVE-2026-58051 in libssh2, urging users to review dependencies and apply updates.

    0000042
    92 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibssh2libssh2---

Explore more