CVE-2025-14821

Published: March 13, 2026Last modified: March 16, 2026

Description

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

Severity score breakdown

ParameterValue
Base score7
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Notes

Only affects libssh on Windows.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibsshNot affected (0.10.4-r0)
25 LTSlibsshNot affected (0.11.1-r0)
StreamlibsshNot affected (0.9.6-r1)

References

ON THIS PAGE