Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
ID: df0cfc59-b03c-56a3-99d8-60adcacfced4
STIX ID: report--df0cfc59-b03c-56a3-99d8-60adcacfced4
Feed Name: The Hacker News
A critical libssh2 vulnerability (CVE-2026-55200, CVSS 9.2) enables a malicious SSH server to craft an oversized packet_length that causes an integer overflow and heap buffer overflow in clients (libssh2 ≤ 1.11.1), potentially allowing code execution; a public proof-of-concept exists but no confirmed in-the-wild exploitation yet, and patches/backports are being applied—organizations should inventory bundled/static copies of libssh2, apply the patch (commit 97acf3d) or vendor updates, and restrict outbound SSH until mitigated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
