CVE-2026-55200

Published Jun 17, 2026

Last updated a month ago

CVSS critical 9.2
SSH
Curl
Tunneling protocol
Port (22)

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-55200 describes an out-of-bounds write vulnerability found in libssh2 versions up to and including 1.11.1. The flaw resides within the `ssh2_transport_read()` function, which fails to properly enforce upper bounds on the `packet_length` field during the reading of incoming SSH packets. This oversight allows remote attackers to send specially crafted SSH packets containing excessively large `packet_length` values. By exploiting this vulnerability, an attacker can corrupt heap memory, potentially leading to remote code execution on affected systems. The issue was addressed in commit 7acf3df of the libssh2 project.

Description
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.
Source
disclosure@vulncheck.com
NVD status
Analyzed
Products
libssh2

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
8.3
Impact score
5.5
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Severity
HIGH

Weaknesses

disclosure@vulncheck.com
CWE-680

Social media

Hype score
Not currently trending
  1. CVE-2026-55200: Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw 0day Intel: Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw htt

    @lyrie_ai

    18 Jul 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 08:25 UTC: CVE-2026-55200 disclosed. Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw 0day Intel: Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw htt

    @lyrie_ai

    18 Jul 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 18:15 UTC: CVE-2026-55200 disclosed. 🚨 Here is another PoC for CVE-2026-55200 - Critical libssh2 Out-of-Bounds Write Vulnerability PoC: 0day Intel: 🚨 Here is another PoC for CVE-2026-55200 - Critical libssh2 Out-of-Bounds Write

    @lyrie_ai

    15 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. ⚠️ Vulnerabilidades en productos SSH ❗ CVE-2026-55200 ❗ CVE-2026-55199 ❗ CVE-2025-15661 ➡️ Más info: https://t.co/9xhRfNiMrO https://t.co/9p3ghUfVJj

    @CERTpy

    14 Jul 2026

    254 Impressions

    1 Retweet

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. The critical libssh2 CVE-2026-55200 flaw inverts SSH security: the remote server attacks the connecting client, no credentials needed. A public PoC is out and the official patched release has not shipped. libssh2 CVE-20... https://t.co/vExXzoMSI7

    @pedri77

    13 Jul 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) | Codebook|Security News https://t.co/NGnxaYYb9X

    @fd0

    5 Jul 2026

    536 Impressions

    0 Retweets

    3 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 ya existe un PoC público para la vulnerabilidad crítica CVE-2026-55200 en libssh2. Si administras servidores o aplicaciones que usan SSH, actualiza de inmediato y revisa tus dependencias para reducir el riesgo de ejecución remota de código. #Ciberseguridad #CyberSecurity

    @CiberneticaChis

    5 Jul 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 📝 When the SSH Server Attacks the Client: libssh2 CVE-2026-55200 You spent years hardening sshd. This bug does not care. CVE-2026-55200 is a pre-auth heap overflow i https://t.co/OHnmPoQ6Ii #DevOps #Security

    @thedevopsdaily

    4 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) https://t.co/OZreuEoWQc

    @crossbreed_dog

    4 Jul 2026

    38 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  10. 匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) https://t.co/Bqw7agdx3U

    @ragemax

    1 Jul 2026

    423 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Critical RCE in libssh2 (CVE-2026-55200) reported today (June 30, 2026) impacts secure transport, risking data privacy/integrity. Cisco CUCM (CVE-2026-20230) actively exploited since June 29. Patch ASAP. #Cybersecurity #Vulnerability #News

    @YourAnon_irc

    30 Jun 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) | Codebook|Security News https://t.co/1ICgrseNLp

    @ohhara_shiojiri

    30 Jun 2026

    80 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. ⚠️匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) 〜サイバーアラート6月30日〜 https://t.co/QjIVS2Mp07

    @MachinaRecord

    30 Jun 2026

    204 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. ⚡ Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw Critical CVE: A public proof-of-concept is now out for CVE-2026-55200, a critical fl... https://t.co/cq4blhj73Q #CVE #CyberSecurity #TechNews #InfoSec

    @MyDooM15

    29 Jun 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🔒 #CyberSecurity CVE-2026-55200: Critical libssh2 Client Flaw — Detection and Hardening Guide "A public PoC for CVE-2026-55200 exposes a critical libssh2 flaw allowing RCE via malicious SSH…" 🔗 https://t.co/aVWQZc7cGJ #CyberSecurity #ThreatIntel #cve #zeroday #patch

    @SecurityAr58409

    29 Jun 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. libssh2: CVE-2026-55200 (critical), CVE-2025-15661 (high), CVE-2026-55199 (high) https://t.co/hF8ZpS6vP6 libssh2 CVE-2026-55200 PoC and local RCE scaffold https://t.co/0v2Iymh7l6

    @oss_security

    25 Jun 2026

    853 Impressions

    2 Retweets

    7 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  17. 🚨 CVE-2026-55200 🚨 Description: libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively

    @bcs_erictaylor

    24 Jun 2026

    88 Impressions

    1 Retweet

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  18. libssh2の重大な脆弱性CVE-2026-55200により、リモートコード実行が可能になります Critical libssh2 Vulnerability CVE-2026-55200 Enables Remote Code Execution #DailyCyberSecurity (Jun 23) https://t.co/RYJ5EVPn95

    @foxbook

    24 Jun 2026

    248 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. My new baby: #CVE-2026-55200 Exploit Kit #libssh2 Out-of-Bounds Write RCE via Unchecked packet_length exploitation framework for **CVE-2026-55200**, targeting> libssh2 out-of-bounds write vulnerability in `transport.c` / `ssh2_tran> #exploit #0days #security #hacking

    @ThomasMaur8sgp

    24 Jun 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. libssh2 Client-Side Heap-Overflow RCE (CVE-2026-55200) and Pre-Auth DoS (CVE-2026-55199) Direct: https://t.co/bvz86RVZmo https://t.co/0ipkD4wS4E

    @NewMaxxSSD

    24 Jun 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. libssh2 CVE-2026-55200 PoC and local RCE scaffold https://t.co/jCH338qRqj #cybersec #threatintel #cve

    @LandscapeThreat

    23 Jun 2026

    30 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations