CVE-2026-55200 Details
Description
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.
A critical out-of-bounds write vulnerability has been identified in libssh2 versions prior to 1.11.1. The issue arises in the ssh2_transport_read() function, where the packet_length field is not properly validated. This flaw enables remote attackers to send crafted SSH packets with excessively large packet_length values, leading to heap memory corruption and potentially allowing for remote code execution.
Users can upgrade to libssh2 version 1.11.1 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-680 | Integer Overflow to Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libssh2 libssh2 | 1.11.1 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | Modified Analysis | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | Modified Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |