CVE-2025-8114: Libssh

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.

Affected products

  • Libssh Libssh: up to and including 0.11.2

Published 2025-07-24. Last modified 2026-09-01.