CVE-2026-55200
Published Jun 17, 2026
Last updated a month ago
AI description
CVE-2026-55200 describes an out-of-bounds write vulnerability found in libssh2 versions up to and including 1.11.1. The flaw resides within the `ssh2_transport_read()` function, which fails to properly enforce upper bounds on the `packet_length` field during the reading of incoming SSH packets. This oversight allows remote attackers to send specially crafted SSH packets containing excessively large `packet_length` values. By exploiting this vulnerability, an attacker can corrupt heap memory, potentially leading to remote code execution on affected systems. The issue was addressed in commit 7acf3df of the libssh2 project.
- Description
- libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.
- Source
- disclosure@vulncheck.com
- NVD status
- Analyzed
- Products
- libssh2
CVSS 4.0
- Type
- Secondary
- Base score
- 9.2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 8.3
- Impact score
- 5.5
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
- Severity
- HIGH
- disclosure@vulncheck.com
- CWE-680
- Hype score
- Not currently trending
CVE-2026-55200: Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw 0day Intel: Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw htt
@lyrie_ai
18 Jul 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
08:25 UTC: CVE-2026-55200 disclosed. Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw 0day Intel: Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw htt
@lyrie_ai
18 Jul 2026
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
18:15 UTC: CVE-2026-55200 disclosed. 🚨 Here is another PoC for CVE-2026-55200 - Critical libssh2 Out-of-Bounds Write Vulnerability PoC: 0day Intel: 🚨 Here is another PoC for CVE-2026-55200 - Critical libssh2 Out-of-Bounds Write
@lyrie_ai
15 Jul 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️ Vulnerabilidades en productos SSH ❗ CVE-2026-55200 ❗ CVE-2026-55199 ❗ CVE-2025-15661 ➡️ Más info: https://t.co/9xhRfNiMrO https://t.co/9p3ghUfVJj
@CERTpy
14 Jul 2026
254 Impressions
1 Retweet
0 Likes
1 Bookmark
0 Replies
0 Quotes
The critical libssh2 CVE-2026-55200 flaw inverts SSH security: the remote server attacks the connecting client, no credentials needed. A public PoC is out and the official patched release has not shipped. libssh2 CVE-20... https://t.co/vExXzoMSI7
@pedri77
13 Jul 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) | Codebook|Security News https://t.co/NGnxaYYb9X
@fd0
5 Jul 2026
536 Impressions
0 Retweets
3 Likes
2 Bookmarks
0 Replies
0 Quotes
🚨 ya existe un PoC público para la vulnerabilidad crítica CVE-2026-55200 en libssh2. Si administras servidores o aplicaciones que usan SSH, actualiza de inmediato y revisa tus dependencias para reducir el riesgo de ejecución remota de código. #Ciberseguridad #CyberSecurity
@CiberneticaChis
5 Jul 2026
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
📝 When the SSH Server Attacks the Client: libssh2 CVE-2026-55200 You spent years hardening sshd. This bug does not care. CVE-2026-55200 is a pre-auth heap overflow i https://t.co/OHnmPoQ6Ii #DevOps #Security
@thedevopsdaily
4 Jul 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) https://t.co/OZreuEoWQc
@crossbreed_dog
4 Jul 2026
38 Impressions
0 Retweets
1 Like
1 Bookmark
1 Reply
0 Quotes
匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) https://t.co/Bqw7agdx3U
@ragemax
1 Jul 2026
423 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Critical RCE in libssh2 (CVE-2026-55200) reported today (June 30, 2026) impacts secure transport, risking data privacy/integrity. Cisco CUCM (CVE-2026-20230) actively exploited since June 29. Patch ASAP. #Cybersecurity #Vulnerability #News
@YourAnon_irc
30 Jun 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) | Codebook|Security News https://t.co/1ICgrseNLp
@ohhara_shiojiri
30 Jun 2026
80 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
⚠️匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) 〜サイバーアラート6月30日〜 https://t.co/QjIVS2Mp07
@MachinaRecord
30 Jun 2026
204 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
⚡ Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw Critical CVE: A public proof-of-concept is now out for CVE-2026-55200, a critical fl... https://t.co/cq4blhj73Q #CVE #CyberSecurity #TechNews #InfoSec
@MyDooM15
29 Jun 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-55200: Critical libssh2 Client Flaw — Detection and Hardening Guide "A public PoC for CVE-2026-55200 exposes a critical libssh2 flaw allowing RCE via malicious SSH…" 🔗 https://t.co/aVWQZc7cGJ #CyberSecurity #ThreatIntel #cve #zeroday #patch
@SecurityAr58409
29 Jun 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
libssh2: CVE-2026-55200 (critical), CVE-2025-15661 (high), CVE-2026-55199 (high) https://t.co/hF8ZpS6vP6 libssh2 CVE-2026-55200 PoC and local RCE scaffold https://t.co/0v2Iymh7l6
@oss_security
25 Jun 2026
853 Impressions
2 Retweets
7 Likes
1 Bookmark
0 Replies
0 Quotes
🚨 CVE-2026-55200 🚨 Description: libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively
@bcs_erictaylor
24 Jun 2026
88 Impressions
1 Retweet
2 Likes
1 Bookmark
0 Replies
0 Quotes
libssh2の重大な脆弱性CVE-2026-55200により、リモートコード実行が可能になります Critical libssh2 Vulnerability CVE-2026-55200 Enables Remote Code Execution #DailyCyberSecurity (Jun 23) https://t.co/RYJ5EVPn95
@foxbook
24 Jun 2026
248 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
My new baby: #CVE-2026-55200 Exploit Kit #libssh2 Out-of-Bounds Write RCE via Unchecked packet_length exploitation framework for **CVE-2026-55200**, targeting> libssh2 out-of-bounds write vulnerability in `transport.c` / `ssh2_tran> #exploit #0days #security #hacking
@ThomasMaur8sgp
24 Jun 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
libssh2 Client-Side Heap-Overflow RCE (CVE-2026-55200) and Pre-Auth DoS (CVE-2026-55199) Direct: https://t.co/bvz86RVZmo https://t.co/0ipkD4wS4E
@NewMaxxSSD
24 Jun 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
libssh2 CVE-2026-55200 PoC and local RCE scaffold https://t.co/jCH338qRqj #cybersec #threatintel #cve
@LandscapeThreat
23 Jun 2026
30 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "00D62356-F677-41CF-AC66-2871AD2112BA",
"versionEndIncluding": "1.11.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]