CVE-2026-55200
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.2EPSS 0.9%KEV nãoPoC públicaNuclei —Metasploit —Patch referenciado
Lifecycle
17 Jun 2026Published on NVD
23 Jun 2026Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
libssh2 · libssh2public PoCs found — 2
githubgithub.com/0xBlackash/CVE-2026-55200★ 8cve_referencegithub.com/bikini/exploitarium/tree/main/libssh2-cve-2026-55200-pocunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/bikini/exploitarium/tree/main/libssh2-cve-2026-55200-pochttps://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8https://github.com/libssh2/libssh2/pull/2052https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c