Critical Remote Code Execution Vulnerability in libssh2
Successful exploitation could allow unauthenticated attackers to achieve remote code execution via crafted SSH packets
Summary
Successful exploitation could allow unauthenticated attackers to achieve remote code execution via crafted SSH packets
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The libssh2 project has released security updates to address a critical vulnerability in libssh2. Remote unauthenticated attackers could send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution (RCE).
- CVE-2026-55200 - 'Integer Overflow to Buffer Overflow' vulnerability - CVSSv4 Base Score: 9.2
Remediation advice
Affected organisations are encouraged to review libssh2 advisory GHSA-R8MH-X5QV-7GG2 and apply the relevant update as soon as possible.
Definitive source of threat updates
Last edited: 23 June 2026 2:17 pm