7.5

CVE-2026-59849

Libssh: libssh: denial of service via automatic certificate authentication loop

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libssh ≫ Libssh Version >= 0.11.0 < 0.11.5
Libssh ≫ Libssh Version 0.12.0
Redhat ≫ Hardened Images Version -
Redhat ≫ Enterprise Linux Version 10.0
Redhat ≫ Enterprise Linux Version 10.0 HwPlatform arm64
Redhat ≫ Enterprise Linux Version 10.0 HwPlatform x64
Redhat ≫ Enterprise Linux Version 10.2 HwPlatform arm64
Redhat ≫ Enterprise Linux Version 10.2 HwPlatform x64
Redhat ≫ Enterprise Linux For Els Version 10.2 HwPlatform arm64
Redhat ≫ Enterprise Linux For Els Version 10.2 HwPlatform x64
Redhat ≫ Enterprise Linux For Eus Version 10.2 HwPlatform arm64
Redhat ≫ Enterprise Linux For Eus Version 10.2 HwPlatform x64
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.159
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
RedHat 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

https://access.redhat.com/security/cve/CVE-2026-59849
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2498182
Vendor Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:42922
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:55855
Vendor Advisory