CVE-2026-59846 PUBLISHED

Libssh: libssh: information disclosure via proxycommand %r username expansion

Assigner: redhat
Reserved: 07.07.2026 Published: 21.07.2026 Updated: 21.07.2026

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CVSS Score: 3.9

Product Status

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 8
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected
Vendor Red Hat
Product Red Hat Hardened Images
Versions Default: affected

Workarounds

Make sure you are not executing connections with untrusted username inputs.

Credits

  • Red Hat would like to thank Mikhail Ilin and Saransh Rana for reporting this issue.

References