A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Do not connect to untrusted SFTP servers.
References
History
Tue, 21 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. | |
| Title | Libssh: libssh: denial of service via sftp responses with unknown request ids | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-21T13:21:50.027Z
Reserved: 2026-07-07T15:40:24.561Z
Link: CVE-2026-59848
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.