No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops. | |
| Title | libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler | |
| First Time appeared |
Libssh2
Libssh2 libssh2 |
|
| Weaknesses | CWE-835 | |
| CPEs | cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libssh2
Libssh2 libssh2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-18T15:31:59.479Z
Reserved: 2026-06-16T15:53:37.764Z
Link: CVE-2026-55199
Updated: 2026-06-18T15:31:52.633Z
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')