CVE-2026-58051: LIBSSH2
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
Affected products
- LIBSSH2 LIBSSH2: up to and including 1.11.1
Published 2026-06-28. Last modified 2026-06-30.