Flaw in libssh Affects Public Key Authentication Functionality
CVE-2026-59849

3.1LOW

What is CVE-2026-59849?

A flaw exists in libssh where logic errors in automatic certificate-based public key authentication could lead to libssh clients entering an infinite loop. This occurs when the configured certificates are not present or are continuously rejected by the server, resulting in a denial of service situation. Such vulnerabilities highlight the critical need for robust error handling and validation in security protocols to prevent exploitation by malicious actors.

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank AISLE Research for reporting this issue.
.