{"cvss":7.8,"datePublished":"2026-04-07T17:16:25.433","dateUpdated":"2026-08-31T12:17:52.850","description":"A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\\etc directory, which can be created and modified by unprivileged local users.","id":"CVE-2025-14821","raw":{"affected":[{"affectedData":[{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:hummingbird:1"],"defaultStatus":"affected","packageName":"libssh-main","product":"Red Hat Hardened Images","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0.12.0-1.1.hum1","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10"],"defaultStatus":"unaffected","packageName":"libssh","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:6"],"defaultStatus":"unaffected","packageName":"libssh2","product":"Red Hat Enterprise Linux 6","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:7"],"defaultStatus":"unaffected","packageName":"libssh2","product":"Red Hat Enterprise Linux 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"unaffected","packageName":"libssh","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"unaffected","packageName":"libssh","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"unaffected","packageName":"openshift/ose-rhel-coreos-8","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"unaffected","packageName":"openshift/ose-rhel-coreos-9","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"}],"source":"secalert@redhat.com"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*","matchCriteriaId":"98F11330-9F92-415F-9F48-6481E0040C46","versionEndExcluding":"0.12.0","vulnerable":true},{"criteria":"cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*","matchCriteriaId":"87DEB507-5B64-47D7-9A50-3B87FD1E571F","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\\etc directory, which can be created and modified by unprivileged local users."}],"id":"CVE-2025-14821","lastModified":"2026-08-31T12:17:52.850","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":1.8,"impactScore":5.9,"source":"secalert@redhat.com","type":"Secondary"},{"cvssData":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":1.0,"impactScore":5.9,"source":"nvd@nist.gov","type":"Primary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2025-14821","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","timestamp":"2026-04-07T00:00:00+00:00","version":"2.0.3"}}]},"published":"2026-04-07T17:16:25.433","references":[{"source":"secalert@redhat.com","tags":["Third Party Advisory"],"url":"https://access.redhat.com/errata/RHSA-2026:7067"},{"source":"secalert@redhat.com","tags":["Third Party Advisory"],"url":"https://access.redhat.com/security/cve/CVE-2025-14821"},{"source":"secalert@redhat.com","tags":["Issue Tracking","Third Party Advisory"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2423148"},{"source":"secalert@redhat.com","tags":["Release Notes"],"url":"https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"}],"sourceIdentifier":"secalert@redhat.com","vulnStatus":"Analyzed","weaknesses":[{"description":[{"lang":"en","value":"CWE-427"}],"source":"secalert@redhat.com","type":"Secondary"}]},"severity":"HIGH","source":"nvd","title":"A flaw was found in libssh"}