CVE-2025-8114: Libssh
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.
Affected products
- Libssh Libssh: up to and including 0.11.2
Published 2025-07-24. Last modified 2026-09-01.