CVE-2026-55200

🟠 Łataj w tym tygodniu

Wykryta podatność w libssh2 umożliwia zdalne wykonanie kodu przez nadmiarowe zapisy w pamięci.

CVSS
8.1
EPSS
4.0%
Exploit
poc
Vendor
libssh2
Opis źródłowy (NVD)

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

exploit rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)4.0%
Opublikowano (NVD)2026-06-17 20:17:28 UTC
Ostatnia modyfikacja (NVD)2026-09-17 17:04:42 UTC
Referencje