Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

ubuntu логотип

CVE-2026-55199

около 2 месяцев назад

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-55199

около 2 месяцев назад

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-55199

около 2 месяцев назад

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2026-55199

около 1 месяца назад

libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-55199

около 2 месяцев назад

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authen ...

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3082-1

17 дней назад

Security update for libssh2_org

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3076-1

17 дней назад

Security update for libssh2_org

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3074-1

18 дней назад

Security update for libssh2_org

EPSS: Низкий
github логотип

GHSA-3cfq-4xx4-rmpg

около 2 месяцев назад

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21057-1

около 1 месяца назад

Security update for libssh2_org

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-55199

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

CVSS3: 5.9
1%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-55199

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

CVSS3: 5.9
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-55199

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

CVSS3: 5.9
1%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-55199

libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler

CVSS3: 5.9
1%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-55199

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authen ...

CVSS3: 5.9
1%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3082-1

Security update for libssh2_org

1%
Низкий
17 дней назад
suse-cvrf логотип
SUSE-SU-2026:3076-1

Security update for libssh2_org

1%
Низкий
17 дней назад
suse-cvrf логотип
SUSE-SU-2026:3074-1

Security update for libssh2_org

1%
Низкий
18 дней назад
github логотип
GHSA-3cfq-4xx4-rmpg

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

CVSS3: 5.9
1%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21057-1

Security update for libssh2_org

около 1 месяца назад

Уязвимостей на страницу