7.5

CVE-2026-59849

Libssh: libssh: denial of service via automatic certificate authentication loop

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LibsshLibssh Version-
RedhatHardened Images Version-
RedhatEnterprise Linux Version10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.159
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
RedHat 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

https://access.redhat.com/security/cve/CVE-2026-59849
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2498182
Vendor Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:42922
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:55855