CVE-2026-0967
5.5 MEDIUMA flaw was found in libssh
Published: 2026-03-26 · Last updated: 2026-05-19
Severity and scoring
- CVSS
- 5.5 MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- CWE
- CWE-1333
Affected products
| Vendor | Product |
|---|---|
| libssh | enterprise_linux, libssh |
| redhat | enterprise_linux, libssh |
Description
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-0967
- [Other]https://access.redhat.com/errata/RHSA-2026:18160
- [Other]https://access.redhat.com/errata/RHSA-2026:18683
- [Other]https://access.redhat.com/security/cve/CVE-2026-0967
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=2436981
- [Other]https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/
Related CVEs
Same vendor
- CVE-2026-1767 — A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component (5.6 MEDIUM)
- CVE-2026-1766 — A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 com... (5.6 MEDIUM)
- CVE-2026-11793 — A stack buffer overflow flaw was found in 389 Directory Server (4.9 MEDIUM)
- CVE-2026-11790 — A flaw was found in 389 Directory Server (4.9 MEDIUM)
- CVE-2026-11789 — A flaw was found in 389 Directory Server (4.9 MEDIUM)
Same CWE
- CVE-2026-47138 — Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
- CVE-2026-44496 — Axios is a promise based HTTP client for the browser and Node.js (7.5 HIGH)
- CVE-2026-42567 — Svelte is a performance oriented web framework (7.5 HIGH)
- CVE-2026-41848 — Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which... (3.7 LOW)
- CVE-2026-52778 — YesWiki is a wiki system written in PHP (9.8 CRITICAL)