Skip to main content
HIGH

CVE-2025-5987

CVSS v3

8.1

HIGH

EPSS Score

1.5 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or

Technical details

Published
2025-07-07
Last Modified
2026-03-20

Frequently asked questions

What is CVE-2025-5987?

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or

Is CVE-2025-5987 actively exploited?

Active exploitation of CVE-2025-5987 has not been confirmed. Its EPSS score was 1.5% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-5987?

CVE-2025-5987 has a CVSS v3 base score of 8.1 (HIGH severity).

Is CVE-2025-5987 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key