Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-15370

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 5.5%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2026-15370


Contact Us

Shodan ® - All rights reserved