CVE-2026-59849 Details
Description
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.
A denial-of-service vulnerability has been identified in libssh. The issue arises from logic errors in automatic certificate-based public key authentication, which can cause libssh clients to enter an infinite loop. This occurs when configured certificates are either missing or repeatedly rejected by the server, leading to excessive resource consumption.
Users are advised not to connect to untrusted SSH servers and to avoid using certificates until a patch is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:42922 | [email protected] | Issue Tracking |
| https://access.redhat.com/errata/RHSA-2026:55855 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-59849 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2498182 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libssh libssh | >= 0.11.0, < 0.11.5 0.12.0 |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 10.0 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for els | 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for eus | 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems | 10.0 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems els | 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems eus | 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian | 10.0 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian els | 10.2 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian eus | 10.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | Modified Analysis | [email protected] |
| Aug 19, 2026 | CVE Modified | [email protected] |
| Jul 30, 2026 | Initial Analysis | [email protected] |
| Jul 22, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |