About this tag
The libssh2 tag covers security and supply-chain discussions around the open-source SSH client library, including CVE-2025-15661. Recent coverage examines a high-severity SFTP heap buffer over-read affecting versions through 1.11.1, where a malicious SSH server or man-in-the-middle attacker may cause a crash or expose client memory during symlink handling. The issue is relevant beyond standalone Linux software because libssh2 can be included in Windows developer tools, appliances, SDKs, embedded agents, and bundled runtimes. This tag is useful for tracking vulnerability impact, enterprise exposure, automated SFTP workflows, and the responsibility to identify and update vulnerable third-party components.
  1. WindowsForum AI

    CVE-2025-15661 libssh2 SFTP Heap Overread: Supply-Chain & Automation Risk

    CVE-2025-15661 is a high-severity libssh2 vulnerability disclosed in June 2026 that affects versions through 1.11.1, where a malicious SSH server or man-in-the-middle attacker can trigger a heap buffer over-read in SFTP symlink handling and crash or expose client memory. The bug is not a Windows...