CVE-2026-66035 | libssh2 up to 1.11.1 Encrypt-then-MAC Cipher Negotiation src/transport.c fullpacket heap-based overflow

SecurityVulns

A vulnerability, which was classified as critical, was found in libssh2 up to 1.11.1. Affected is the function fullpacket of the file src/transport.c of the component Encrypt-then-MAC Cipher Negotiation. The manipulation results in heap-based buffer overflow.

This vulnerability is identified as CVE-2026-66035. The attack can be executed remotely. There is not any exploit available.

A patch should be applied to remediate this issue.VulDB Recent EntriesRead More