๐Ÿ” CVE Alert

CVE-2026-55199

MEDIUM 5.9

libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.

CWE CWE-835
Vendor libssh2
Product libssh2
Published Jun 17, 2026
Stay Ahead of the Next One

Get instant alerts for libssh2 libssh2

Be the first to know when new medium vulnerabilities affecting libssh2 libssh2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

libssh2 / libssh2
0 โ‰ค 1.11.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/libssh2/libssh2/pull/1864 github.com: https://github.com/libssh2/libssh2/commit/17626857d20b3c9a1addfa45979dadcee1cd84a4 vulncheck.com: https://www.vulncheck.com/advisories/libssh2-pre-authentication-dos-via-ssh-msg-ext-info-handler

Credits

Tristan Madani (@TristanInSec)