Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59846

Опубликовано: 21 июл. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsshfixed0.12.1-1package

Примечания

  • https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/

  • https://www.libssh.org/security/advisories/CVE-2026-59846.txt

  • Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=2e74267b034f00e8e36c86440364f885cead5f45 (libssh-0.12.1)

EPSS

Процентиль: 2%
0.00115
Низкий

Связанные уязвимости

CVSS3: 3.9
ubuntu
12 дней назад

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

CVSS3: 3.9
redhat
12 дней назад

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

CVSS3: 3.9
nvd
12 дней назад

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

msrc
8 дней назад

Libssh: libssh: information disclosure via proxycommand %r username expansion

CVSS3: 3.9
github
12 дней назад

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

EPSS

Процентиль: 2%
0.00115
Низкий