Security Advisory

CVE-2026-59844

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-21 11:32:16
Last updated 2026-08-17 21:54:14
Assigner redhat
CVSS score 6.5
State PUBLISHED

Description

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.