<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:29:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06714</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06714</link>
      <description>bdu:2026-06714</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06714</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-3731</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-3731</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libssh, Alpaquita:25: libssh, Alpaquita:stream: libssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libssh, Alpaquita:25: libssh, Alpaquita:stream: libssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-3731</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0316 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</link>
      <description>certfr-2026-avi-0316</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</guid>
    </item>
    <item>
      <title>EUVD-2026-275635</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275635</link>
      <description>EUVD-2026-275635</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275635</guid>
    </item>
    <item>
      <title>fkie_cve-2026-3731</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-3731</link>
      <description>&lt;p&gt;A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-3731</guid>
    </item>
    <item>
      <title>GHSA-wg5h-wgv3-pgqh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wg5h-wgv3-pgqh</link>
      <description>&lt;p&gt;A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wg5h-wgv3-pgqh</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-3731 — libssh SFTP Extension Name sftp.c sftp_extensions_get_data out-of-bounds</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-3731</link>
      <description>msrc_CVE-2026-3731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-3731</guid>
    </item>
    <item>
      <title>OESA-2026-1560 — libssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1560</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: libssh&lt;/p&gt;
&lt;p&gt;The ssh library was designed to be used by programmers needing a working SSH implementation by the mean of a library. The complete control of the client is made by the programmer. With libssh, you can remotely execute programs, transfer files, use a secure and transparent tunnel for your remote programs. With its Secure FTP implementation, you can play with remote files easily, without third-party programs others than libcrypto (from openssl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;(CVE-2026-0964)&lt;/p&gt;
&lt;p&gt;(CVE-2026-0965)&lt;/p&gt;
&lt;p&gt;(CVE-2026-0966)&lt;/p&gt;
&lt;p&gt;(CVE-2026-0967)&lt;/p&gt;
&lt;p&gt;(CVE-2026-0968)&lt;/p&gt;
&lt;p&gt;A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.(CVE-2026-3731)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: libssh&lt;/p&gt;
&lt;p&gt;The ssh library was designed to be used by programmers needing a working SSH implementation by the mean of a library. The complete control of the client is made by the programmer. With libssh, you can remotely execute programs, transfer files, use a secure and transparent tunnel for your remote programs. With its Secure FTP implementation, you can play with remote files easily, without third-party programs others than libcrypto (from openssl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;(CVE-2026-0964)&lt;/p&gt;
&lt;p&gt;(CVE-2026-0965)&lt;/p&gt;
&lt;p&gt;(CVE-2026-0966)&lt;/p&gt;
&lt;p&gt;(CVE-2026-0967)&lt;/p&gt;
&lt;p&gt;(CVE-2026-0968)&lt;/p&gt;
&lt;p&gt;A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.(CVE-2026-3731)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1560</guid>
    </item>
    <item>
      <title>RHSA-2026:7067 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:7067</link>
      <description>&lt;p&gt;libssh: libssh: Insecure default configuration leads to local man-in-the-middle attacks on Windows libssh: libssh: Denial of Service via zero-length input in ssh_get_hexa() libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libssh: libssh: Insecure default configuration leads to local man-in-the-middle attacks on Windows libssh: libssh: Denial of Service via zero-length input in ssh_get_hexa() libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:7067</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0936-1 — Security update for libssh</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0936-1</link>
      <description>&lt;p&gt;Security update for libssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0936-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-3731</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-3731</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libssh, Ubuntu:Pro:18.04:LTS: libssh, Ubuntu:Pro:20.04:LTS: libssh, Ubuntu:22.04:LTS: libssh, Ubuntu:24.04:LTS: libssh, Ubuntu:25.10: libssh, Ubuntu:26.04:LTS: libssh&lt;/p&gt;
&lt;p&gt;A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libssh, Ubuntu:Pro:18.04:LTS: libssh, Ubuntu:Pro:20.04:LTS: libssh, Ubuntu:22.04:LTS: libssh, Ubuntu:24.04:LTS: libssh, Ubuntu:25.10: libssh, Ubuntu:26.04:LTS: libssh&lt;/p&gt;
&lt;p&gt;A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-3731</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0634 — libssh: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0634</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libssh ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libssh ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0634</guid>
    </item>
  </channel>
</rss>
