CVE-2026-7598 Details
Description
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.
A security vulnerability allowing for integer overflow has been identified in libssh2 versions through 1.11.1. The issue arises in the userauth_password function within src/userauth.c, where improper handling of the username_len and password_len arguments can be exploited remotely.
Users are advised to update to the latest version of libssh2, where this vulnerability has been addressed. The specific commit that resolves this issue is 256d04b60d80bf1190e96b0ad1e91b2174d744b1.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:16736 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:61752 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:7021 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-7598 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464597 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7598.json | redhat-SADP | |
| https://vuldb.com/submit/805564 | CISA-ADP | Third Party AdvisoryVDB Entry |
| https://github.com/libssh2/libssh2/ | [email protected] | Product |
| https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1 | [email protected] | Patch |
| https://github.com/libssh2/libssh2/pull/1858 | [email protected] | Issue Tracking |
| https://vuldb.com/submit/805564 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/360555 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/360555/cti | [email protected] | Permissions RequiredVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-189 | Numeric Errors | [email protected] |
| CWE-190 | Integer Overflow or Wraparound | redhat-SADP |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libssh2 libssh2 | <= 1.11.1 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | redhat-SADP |
| Sep 1, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 7, 2026 | Initial Analysis | [email protected] |
| May 4, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | New CVE Received | [email protected] |