CVE-2017-18594: Nmap
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
Affected products
- Nmap Nmap: version 7.70 only
Published 2019-08-29. Last modified 2026-06-17.