CVE-2026-0966

ADVISORY - nist

Summary

A flaw was found in libssh. The API function ssh_get_hexa() is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to SSH_LOG_PACKET (3) or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process.

EPSS Score: 0.00582 (0.445)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Buffer Underwrite ('Buffer Underflow')


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in