CVE-2026-59847CWE-1310CWE-253

CVE-2026-59847

Medium · published July 21, 2026

CVSS v3.1
5.9
EPSS
0%
Percentile
24.2
In the wild
Unconfirmed
What it is

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

The record
Technical detail
CVSS v3.1
5.9 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00317 · 24.2th percentile
Weaknesses
CWE-1310 · Missing Ability to Patch ROM Code; CWE-253 · Incorrect Check of Function Return Value
Published
2026-07-21T18:16Z
Affected products (6)
ProductVersionsFixed in
libssh/libssh≥ 0.9.0, < 0.11.50.11.5
libssh/libsshall versions
redhat/hardened_imagesall versions
redhat/enterprise_linuxall versions
redhat/enterprise_linuxall versions
redhat/enterprise_linuxall versions
References (6)
EPSS history
Timeline
  • 21 JUL 13:18Z
    Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
    cvelistv5