CVE-2026-59844

Summary

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-789: Memory Allocation with Excessive Size Value

Workarounds

No workaround available.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References