Denial of Service Vulnerability in libssh Affects Multiple Clients
CVE-2026-59848
5.3MEDIUM
What is CVE-2026-59848?
A vulnerability exists in libssh, where a malicious SFTP server can exploit queued responses for unknown request IDs, leading to unbounded memory consumption. This can result in a denial of service for clients as their memory usage grows without limit, potentially causing crashes or inaccessibility. Mitigation of this issue requires users to ensure they are running an updated version of libssh.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Aisle Research for reporting this issue.