CVE detail
CVE-2026-55200
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.7 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 9
- within the 30d window
- Peak daily
- 3
- highest bucket
Evidence
Source links by recency
15 source links · newest first
eaponize such vulnerabilities as far back as December 2021. Last October, a stored XSS flaw in the Classic Web Client ( CVE-2025-27915 , CVSS Score: 5.4) was alleged to have been exploited as a zero-day in attacks targeting the Brazilian military, although Zimbra told The Hacker News at the time that it found no evidence to back it up. Other XSS flaws
newsthehackernews.comJul 11, 2026, 6:45 AMprivilege escalation , Sandbox Escape , Vulnerability ⚡ Top Stories This Week Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks AirDrop and Quick Share Flaws Let Nearby A
newsthehackernews.comJul 10, 2026, 2:19 PMemote crashes in HTTP/2 and HTTP/3 stacks. Three weeks earlier, THN reported a use-after-free in NGINX's HTTP/3 module (CVE-2026-42530) that a remote, unauthenticated client could reach through the same QPACK encoder stream XRING abuses, a different bug class on the same attack surface. In June, Calif's HTTP/2 Bomb caused remote denial of service again
newsthehackernews.comJul 10, 2026, 11:47 AM- Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency WalletsThe Hacker News
som," the first weak phrase its generator produces, the same way Milk Sad was named after "milk sad" in 2023. That bug (CVE-2023-39910), in the Libbitcoin Explorer command-line tool, let thieves drain millions in one sweep that July. A close cousin (CVE-2023-31290) hit the Trust Wallet browser extension the same year, crackable in under a day. The same
newsthehackernews.comJul 10, 2026, 9:00 AM es Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild Chrome Ad Blocker with 10M+ Installs Found wit
newsthehackernews.comJul 7, 2026, 1:27 PMd, and FatFs mishandles the bad data. runZero rated the set CVSS Medium to High, with no Criticals. The headline bug is CVE-2026-6682 (CVSS 7.6), an integer overflow in the code that mounts a FAT32 volume. Bad math can produce a false file size, which later code treats as a real read length. On real hardware, that can become memory corruption and code
newsthehackernews.comJul 3, 2026, 8:19 PM- Researcher Behind 'Exploitarium' Explains Release of Undisclosed Zero-Day ExploitsInfosecurity Magazine
Some vulnerabilities have since been publicly disclosed and some of them have been patched by maintainers. One of them, CVE-2026-55200 , represents a severe pre-authentication remote code execution (RCE) vulnerability affecting libssh2, a widely used client-side C library implementing the SSH2 protocol, with a CVSS severity score of 9.2. Exploitation i
newswww.infosecurity-magazine.comJul 2, 2026, 12:51 PM Linked URL: https://github.com/advisories/GHSA-R8MH-X5QV-7GG2 | Posted by wildylion | 4 points | 1 comments
communitynews.ycombinator.comJun 30, 2026, 8:12 PM- Anonymous researcher drops 0-day 'exploitarium' repoThe Register Security
y vendors or maintainers prior to publishing - and attackers are already exploiting at least two of these. The first is CVE-2026-55200, a critical, pre-authentication remote code execution (RCE) vulnerability in libssh2, a popular client-side C library that implements the SSH2 protocol. Remote attackers can send crafted SSH packets with excessively lar
newswww.theregister.comJun 29, 2026, 8:29 PM - CVE-2026-55200 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.cMicrosoft MSRC
Information published.
vendormsrc.microsoft.comJun 28, 2026, 8:49 AM - Remote Code Execution in Libssh2Hacker News
Linked URL: https://vuldb.com/cve/CVE-2026-55200 | Posted by walrus01 | 2 points | 0 comments
communitynews.ycombinator.comJun 18, 2026, 3:56 AM - https://web.archive.org/web/20260623211210/https://github.com/bikini/exploitarium/tree/main/libssh2-cve-2026-55200-pocweb.archive.org
No excerpt available.
Exploitweb.archive.orgJun 17, 2026, 8:17 PM - https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-cwww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comJun 17, 2026, 8:17 PM No excerpt available.
Exploitgithub.comJun 17, 2026, 8:17 PMNo excerpt available.
Exploitgithub.comJun 17, 2026, 8:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-8376CVSS 9.8 · Critical
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c ch…
- CVE-2026-24928CVSS 5.8 · Medium
Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2026-25541CVSS 5.5 · Medium
Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of…
- CVE-2025-53510CVSS 8.8 · High
A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .psd file, an integer…
- CVE-2025-52930CVSS 8.8 · High
A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially craf…
- CVE-2025-52456CVSS 8.8 · High
A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .webp animation an in…