Double Free Vulnerability in RSA KEX of PuTTY by Simon Tatham
CVE-2026-48850

3.7LOW

Key Information:

Vendor

Putty

Status
Vendor
CVE Published:
25 May 2026

What is CVE-2026-48850?

A vulnerability in versions of PuTTY prior to 0.84 allows for a double free condition in the RSA key exchange (KEX) process. This can potentially lead to unexpected behavior in the application, which may be exploited by attackers to execute arbitrary code or crash the program. Users are advised to update to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

PuTTY 0.72 < 0.84

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.