SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-59843

MEDIUM · CVSS 6.5 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A flaw in libssh allows a remote authenticated peer to advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, which can result in an infinite loop during subsequent channel writes, ultimately consuming CPU resources and leading to a denial of service. Organizations using libssh should prioritize this vulnerability to mitigate potential service disruptions. This is particularly relevant for environments where SSH is heavily utilized for remote access and management.

CVE
CVE-2026-59843
Severity
MEDIUM
CVSS
6.5
EPSS
0.53%

Original NVD Description

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)