SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-59848

MEDIUM · CVSS 5.3 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A vulnerability in libssh allows a malicious SFTP server to send responses for unknown request IDs, leading to unbounded memory growth in affected clients. This can result in a denial of service, as the clients may exhaust available memory. Organizations using libssh should prioritize addressing this issue to prevent potential service disruptions.

CVE
CVE-2026-59848
Severity
MEDIUM
CVSS
5.3
EPSS
0.31%

Original NVD Description

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)