A high-severity memory-safety flaw tracked as CVE-2026-66032 was disclosed in libssh2 through version 1.11.1, affecting the sftp_open() function in src/sftp.c. The bug allows a malicious SSH server to trigger a double free in an authenticated client that opens an SFTP session, creating heap corruption conditions. Advisory details say the issue occurs when the server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK and a later sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, causing the same response buffer to be freed twice.
The libssh2 project addressed the flaw in commit 5e4776146552d898b9c0e1b313cd093fa8dc92d0, merged through pull request #2180, by nullifying the pointer after it is freed in the SFTP code. The fix, which also resolves advisory GHSA-px3w-7g75-hg7w, credits VladimirEliTokarev for reporting the issue. Security writeups warn that on glibc-based systems the bug can produce tcache-dup style heap corruption, potentially enabling overlapping allocations and function pointer overwrites, and users are advised to update libssh2 or apply the patch and recompile.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-66032 was published for a high-severity double-free vulnerability in libssh2 through version 1.11.1 affecting sftp_open(). The disclosure states that a malicious SSH server can trigger heap corruption in an authenticated client opening an SFTP session, and notes the issue is fixed by commit 5e4776146552d898b9c0e1b313cd093fa8dc92d0.
A libssh2 pull request to nullify a pointer after freeing it in src/sftp.c was merged into the master branch as commit 5e47761. The change explicitly fixes advisory GHSA-px3w-7g75-hg7w and credits VladimirEliTokarev for the report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.