Root has patched CVE-2026-66035 in the libssh2 package for Root:Debian:13. Multiple fixed versions available.
{
"distro": "debian",
"distro_version": "13",
"severity": "HIGH",
"source": "Root"
}[
"1.11.1-1+deb13u1.aikido.3",
"1.11.1-1+deb13u1.aikido.4",
"1.11.1-1+deb13u1.aikido.5",
"1.11.1-1+deb13u1.aikido.7",
"1.11.1-1+deb13u1.aikido.6"
]
"aikido.7"
true
"https://api.root.io/external/osv/ROOT-OS-DEBIAN-13-CVE-2026-66035.json"
5
"1.11.1-1+deb13u1"
[
"1.11.1-1+deb13u1.aikido.3",
"1.11.1-1+deb13u1.aikido.4",
"1.11.1-1+deb13u1.aikido.5",
"1.11.1-1+deb13u1.aikido.7",
"1.11.1-1+deb13u1.aikido.6"
]
"aikido.7"
true
"https://api.root.io/external/osv/ROOT-OS-DEBIAN-13-CVE-2026-66035.json"
5
"1.11.1-1+deb13u1"