Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Do not connect to untrusted SSH servers and do not use certificates until patched.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6410-1 | libssh security update |
Ubuntu USN |
USN-8699-1 | libssh vulnerabilities |
Tue, 22 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat enterprise Linux For Els
Redhat enterprise Linux For Eus Redhat enterprise Linux For Ibm Z Systems Redhat enterprise Linux For Ibm Z Systems Els Redhat enterprise Linux For Ibm Z Systems Eus Redhat enterprise Linux For Power Little Endian Redhat enterprise Linux For Power Little Endian Els Redhat enterprise Linux For Power Little Endian Eus |
|
| CPEs | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* cpe:2.3:a:libssh:libssh:0.12.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux:10.2:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux:10.2:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux_for_els:10.2:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux_for_els:10.2:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux_for_eus:10.2:*:*:*:*:*:arm64:* cpe:2.3:o:redhat:enterprise_linux_for_eus:10.2:*:*:*:*:*:x64:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_els:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_els:10.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:10.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Redhat enterprise Linux For Els
Redhat enterprise Linux For Eus Redhat enterprise Linux For Ibm Z Systems Redhat enterprise Linux For Ibm Z Systems Els Redhat enterprise Linux For Ibm Z Systems Eus Redhat enterprise Linux For Power Little Endian Redhat enterprise Linux For Power Little Endian Els Redhat enterprise Linux For Power Little Endian Eus |
Wed, 19 Aug 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:enterprise_linux:10.2 | |
| References |
|
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libssh
Libssh libssh Redhat hardened Images |
|
| Vendors & Products |
Libssh
Libssh libssh Redhat hardened Images |
Wed, 22 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 22 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 21 Jul 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. | |
| Title | Libssh: libssh: denial of service via automatic certificate authentication loop | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| Weaknesses | CWE-835 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-19T04:57:42.066Z
Reserved: 2026-07-07T15:40:24.561Z
Link: CVE-2026-59849
Updated: 2026-07-22T14:31:09.232Z
Status : Analyzed
Published: 2026-07-21T15:16:37.647
Modified: 2026-09-22T19:48:05.513
Link: CVE-2026-59849
OpenCVE Enrichment
Updated: 2026-07-30T17:30:17Z
Debian DSA
Ubuntu USN