Critical Vulnerabilities Found in libssh2 SSH Library

Critical Vulnerabilities Found in libssh2 SSH Library

5h ago Heise.Detracker.debian.orgCybernewsnvd.nist.govgithub.com 92% similarity 69.8
Share:

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in libssh2, an SSH library used in millions of systems. The vulnerabilities, CVE-2026-55200 and CVE-2026-55199, allow remote code execution and denial-of-service attacks without user interaction. Affected versions include 1.11.1 and earlier. Attackers can exploit these flaws by sending crafted SSH packets to vulnerable systems. The first vulnerability has a severity score of 9.2, while the second has a score of 8.2. Patches are available in the form of GitHub commits, but an official release has not yet been made. Many Linux distributions are working to backport the fixes. The potential impact is significant, as libssh2 is widely used in sensitive applications, including network management and IoT devices.

Key Points: • Two critical vulnerabilities in libssh2 allow remote code execution and DoS attacks. • Affected versions include 1.11.1 and earlier; patches are available but not yet officially released. • The vulnerabilities could impact millions of systems globally, including IoT devices and servers.

ThreatCluster AI

Timeline

2026-06-17
CVE-2026-55199 published
A denial-of-service vulnerability affecting libssh2 was disclosed, allowing CPU exhaustion on clients.
Cybernews
2026-06-17
CVE-2026-55200 published
A critical out-of-bounds write vulnerability in libssh2 was disclosed, enabling remote code execution.
Cybernews
2026-06-21
Patches identified but not released
Developers confirmed that patches exist as GitHub commits but have not yet been officially released.
Heise.De
Recent
Linux distributions testing patched versions
Debian and Kali Linux are reportedly testing patched versions of libssh2 to mitigate the vulnerabilities.
Heise.De

Community

Browse all →