SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-59844

MEDIUM · CVSS 6.5 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A vulnerability in libssh allows a remote authenticated client to send SSH_FXP_READ requests with excessively large lengths, leading to excessive memory allocation on the SFTP server. This can result in memory exhaustion, potentially causing service disruptions. Organizations utilizing libssh for SFTP services should prioritize addressing this issue to mitigate the risk of denial-of-service attacks.

CVE
CVE-2026-59844
Severity
MEDIUM
CVSS
6.5
EPSS
0.53%

Original NVD Description

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

Related CVEs

Other vulnerabilities affecting the same vendor(s)