SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-59842

LOW · CVSS 3.7 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A vulnerability in Exchange allows for an out-of-bounds heap read due to improper length validation of a client-supplied Curve25519 public key during server-side GSSAPI key exchange. This flaw could enable a remote, unauthenticated attacker to disclose small amounts of server memory, potentially exposing sensitive information. Organizations using affected versions of Exchange should prioritize remediation to mitigate the risk of data leakage.

CVE
CVE-2026-59842
Severity
LOW
CVSS
3.7
EPSS
0.42%
Exchange

Original NVD Description

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)