SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-59845

MEDIUM · CVSS 5.3 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A vulnerability in libssh allows for an unchecked fork() failure when using ProxyCommand, potentially resulting in a process ID of -1. This flaw can lead to local denial of service by sending signals across the caller's accessible process tree during cleanup. Organizations utilizing libssh in their applications should prioritize addressing this issue to mitigate potential disruptions.

CVE
CVE-2026-59845
Severity
MEDIUM
CVSS
5.3
EPSS
0.11%

Original NVD Description

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)