PT-2026-50528 · Libssh2+1 · Libssh2+1

·

CVE-2026-55200

·

Published

2026-06-13

·

Updated

2026-08-01

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libssh2 versions prior to 1.11.2
Description An out-of-bounds write issue exists in the ssh2 transport read() function due to an integer overflow and a failure to enforce upper bounds on the packet length field. A remote attacker operating a malicious SSH server can send crafted SSH packets with excessively large packet length values to trigger heap memory corruption on a connecting client. This flaw allows for remote code execution without requiring user credentials or interaction. The library is widely embedded in applications such as curl, Git, and PHP, potentially enabling service crashes, system takeover, and lateral movement via compromised jump hosts or file-transfer services.
Recommendations Update libssh2 to a version containing the fix implemented in commit 7acf3df. Restrict outbound SSH connections to only trusted servers to minimize the risk of connecting to a malicious server. Inventory all systems, applications, and appliances to identify bundled or static copies of libssh2 for patching.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08612
CVE-2026-55200
ECHO-81B6-9726-71C6
JLSEC-2026-661
OPENSUSE-SU-2026:11109-1
OPENSUSE-SU-2026:21057-1
SUSE-SU-2026:22284-1
SUSE-SU-2026:22364-1
USN-8486-1

Affected Products

Linuxmint
Libssh2