What is CVE-2026-59844?
This critical flaw in the libssh library allows a remote authenticated attacker to force an SFTP server to allocate excessive memory through repeated SSH_FXP_READ requests with large lengths, potentially leading to memory exhaustion. Users must update libssh to the latest patched version or strengthen input validation to mitigate the risk.
Azərbaycanca: Bu kritik boşluq libssh kitabxanasında aşkarlanıb və autentifikasiya olunmuş uzaq istifadəçiyə SFTP serverini həddindən artıq yaddaş ayırmağa məcbur etməyə imkan verir. Təcavüzkar 'SSH_FXP_READ' sorğularını böyük uzunluqlarla təkrarlayaraq yaddaşın tükənməsinə səbəb ola bilər. istifadəçilər libssh-i ən son versiyaya yeniləməli və ya giriş yoxlamasını gücləndirməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What is CVE-2026-59844 and which component does it affect?
CVE-2026-59844 is a critical flaw in the libssh library. It allows a remote authenticated attacker to force an SFTP server to allocate excessive memory through repeated SSH_FXP_READ requests with large lengths, potentially leading to memory exhaustion.
How can one protect against the CVE-2026-59844 vulnerability?
Users must update the libssh library to the latest patched version or strengthen input validation to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.