CVE Watchtower


← Back to CVE List

CVE-2026-55200NVD

Vulnerability Summary

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.
Severity Level
HIGH(8.1)
Published Date
Jun 17, 2026
Last Modified
Jun 18, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.55%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh