SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-59850

MEDIUM · CVSS 4.3 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A vulnerability in libssh allows for the processing of data packets after a channel has been closed, potentially triggering channel data callbacks on already freed memory. This can lead to application crashes or exploitation through use-after-free conditions. Organizations using libssh should prioritize patching this flaw to mitigate risks associated with stability and security.

CVE
CVE-2026-59850
Severity
MEDIUM
CVSS
4.3
EPSS
0.32%

Original NVD Description

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)