« Back to list

CVE-2026-59849

Status: AnalyzedHigh (7.5)—

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (11)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-59849",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-59849",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-22T14:31:02.938864Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.1,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:10.2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 10",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:0.12.0-3.el10_2",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "libssh",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:hummingbird:1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Hardened Images",
          "versions": [
            {
              "status": "unaffected",
              "version": "0.12.1-4.hum1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "libssh-main",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8",
          "packageName": "libssh",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9",
          "packageName": "libssh",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-21T15:16:37.647",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:42922",
      "tags": [
        "Issue Tracking"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:55855",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-59849",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2498182",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-835"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service."
    }
  ],
  "lastModified": "2026-09-22T19:48:05.513",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AB6D376-A470-41DB-BEA0-77F711432B7A",
              "versionEndExcluding": "0.11.5",
              "versionStartIncluding": "0.11.0"
            },
            {
              "criteria": "cpe:2.3:a:libssh:libssh:0.12.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C250851D-1948-4012-ABE4-FEBB369E3231"
            },
            {
              "criteria": "cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87DEB507-5B64-47D7-9A50-3B87FD1E571F"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:arm64:*",
              "vulnerable": true,
              "matchCriteriaId": "63D81CCC-AECF-436A-B019-B3149585F92C"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "472208E5-9850-47CD-8C7D-E1EBF7FDB2C7"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:10.2:*:*:*:*:*:arm64:*",
              "vulnerable": true,
              "matchCriteriaId": "4DBA7603-2980-42BE-981C-FAE97568B00B"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:10.2:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "D28BC9F4-ECC6-411B-B445-B247FACD9530"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_els:10.2:*:*:*:*:*:arm64:*",
              "vulnerable": true,
              "matchCriteriaId": "C78AA720-6EBB-4CA7-8831-22A7CBFE7A1C"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_els:10.2:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "1D055CB8-FA3A-4DB8-AB58-9B17F7EC552B"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_eus:10.2:*:*:*:*:*:arm64:*",
              "vulnerable": true,
              "matchCriteriaId": "ADFDF403-9B07-48CF-8BB2-11054879BCF8"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_eus:10.2:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "E7AB6D4F-D513-45F8-BC00-5F6C93D0002D"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31F91BA6-64D9-4248-8773-6B5B99CA01A0"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "157996FE-FC8B-4D4E-9538-E14BC0D8466F"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_els:10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B8AC302-55C1-44FB-B66C-C6D0D6F5DBFE"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7F02954-7CB7-46F9-BBF1-3FAD6736F712"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06A3271F-112F-4FB7-A2F7-6401A365FCBA"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6F30042-532F-4A7C-897B-1084C0587957"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_els:10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9BB0DAF9-794A-4DAF-A4C6-3DDD8E42F48D"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDDCBC52-F003-4776-8D21-B525CF8D8B8D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}