CVE-2026-66034Libssh2 · Libssh2
Vulnerability data via NVD (ingested)
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-66034product:"Libssh2 Libssh2"http.html:"Libssh2"More intel sources (5)
vuln:CVE-2026-66034vulnerabilities.cve_id: CVE-2026-66034CVE-2026-66034CVE-2026-66034"CVE-2026-66034" exploit -site:nvd.nist.gov