vulnerability
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
Critical
Summary
A critical vulnerability, CVE-2026-55200, has been discovered in libssh2, a client-side SSH library embedded in various applications like curl, Git, and PHP. The flaw allows for code execution via an integer overflow, potentially leading to remote code execution. While a proof-of-concept has been released, the immediate risk is mitigated by ongoing backporting efforts and recommendations for inventorying and restricting outbound SSH connections.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
