CVE-2026-55200
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.
- libssh2
- ≤ 1.11.1
- Fix
- Available
- CVSS 4.0
- 9.2 CRITICAL
- CVSS 3.1
- 8.3 HIGH
- EPSS
- 2.0% (79th percentile)
- Weakness
- CWE-680
- NVD status
- Analyzed
- Published
- 2026-06-17
CVE-2026-55200 at NVD
11 known exploits for CVE-2026-55200
Proof-of-concept code and exploit modules indexed by Sploitus