Resource exhaustion in libssh - CVE-2026-59848
Published: July 27, 2026
libssh
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of unexpected responses in the sftp client response queue when processing server-supplied sftp response packets. A remote attacker can send response packets with unknown request IDs to cause a denial of service.
The issue affects the client side only.