Unbounded Memory DoS in libssh SFTP Client via Unknown Request IDs
CVE-2026-59848 Published on July 21, 2026
Libssh: libssh: denial of service via sftp responses with unknown request ids
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
Vulnerability Analysis
CVE-2026-59848 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Timeline
Reported to Red Hat.
Made public. 83 days later.
Weakness Type
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Products Associated with CVE-2026-59848
stack.watch emails you whenever new vulnerabilities are published in Red Hat Enterprise Linux (RHEL) or Red Hat Hummingbird. Just hit a watch button to start following.
Affected Versions
Red Hat Enterprise Linux 10:- Version 0:0.12.0-3.el10_2 and below * is unaffected.
- Version 0.12.1-4.hum1 and below * is unaffected.