THREAT OPS › Threat News › [NVD] CVE-2026-59842 (LOW 3.7) — A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to di
[NVD] CVE-2026-59842 (LOW 3.7) — A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to di
CVE-2026-59842 CVSS: 3.7 LOW Published: 2026-07-21T12:18:57.727
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.
Indicators of compromise
- CVE-2026-59842cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-59842