---
schema: 1
kind: vulnerability
title: >
  CVE-2026-55200 — libssh2 heap out-of-bounds write in ssh2_transport_read() with public PoC;
  companion pre-auth DoS CVE-2026-55199
headline: >
  CVE-2026-55200 — libssh2 heap out-of-bounds write in ssh2_transport_read() with public PoC;
  companion pre-auth DoS CVE-2026-55199
summary: >
  libssh2 heap out-of-bounds write (CVE-2026-55200, CVSS 9.2) now has a public PoC confirming code
  execution; it is embedded in curl, PHP, WinSCP, FileZilla and many network appliances — a
  malicious/compromised SSH server can corrupt a connecting client's heap (NCSC-NL, 2026-06-24).
discovered_at: "2026-06-28T05:05:39Z"
updated_at: "2026-06-30T05:10:41Z"
event_date: 2026-06-24
run_id: 2026-06-28-1b30612a
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - poc-public
  - rce
  - dos
  - pre-auth
  - supply-chain
regions:
  - global
sectors:
  - technology
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-55200
    cvss: "9.2"
    epss: null
    type: rce
    vector: user-interaction
    auth: pre-auth
    status:
      - poc-public
      - no-patch
  - id: CVE-2026-55199
    cvss: "8.2"
    epss: null
    type: rce
    vector: user-interaction
    auth: pre-auth
    status:
      - poc-public
      - no-patch
sources:
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0210"
    publisher: NCSC-NL NCSC-2026-0210
    role: primary
  - url: "https://github.com/advisories/GHSA-r8mh-x5qv-7gg2"
    publisher: GitHub Advisory GHSA-r8mh-x5qv-7gg2
    role: corroborating
  - url: "https://thehackernews.com/2026/06/public-poc-released-for-critical.html"
    publisher: The Hacker News
    role: primary
  - url: "https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c"
    publisher: VulnCheck
    role: corroborating
closed_sources: []
evidence:
  - quote: "Update (2026-06-24): Publieke PoC code verschenen die bevestigd dat de kwetsbaarheid onder specifieke mogelijkheden kan leiden tot het uitvoeren van willekeurige code"
    publisher: NCSC-NL
  - quote: "Out-of-bounds write flaw in ssh2_transport_read() that fails to enforce upper bounds on packet_length field; CVSS 9.2 Critical"
    publisher: GitHub Advisory GHSA-r8mh-x5qv-7gg2
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Inventory and remediate libssh2** (§ 2, CVE-2026-55200 / -55199): identify embedded libssh2 ≤ 1.11.1 in curl, PHP ssh2, WinSCP/FileZilla and appliances; apply downstream vendor fixes / the patched commits; confirm ASLR is enabled on hosts running SSH-client automation; restrict automation to known SSH endpoints."
updates:
  - at: "2026-06-30T05:10:41Z"
    run_id: 2026-06-30-9aaa1114
    type: update
    summary: >
      Two previously-covered critical CVEs now have public PoCs: libssh2 pre-auth heap write
      (CVE-2026-55200) and the DirtyClone Linux kernel LPE (CVE-2026-43503), the latter with a
      confirmed working exploit on default Debian/Fedora. Separately, the US posted a $10M bounty on
      the Russia-nexus Signal/WhatsApp phishing crews and added Signal Backup Recovery Key theft to
      the advisory — a persistent-access tactic Swiss federal officials using Signal should act on.
    fields:
      - sources
      - tags
      - body
    merged_from: 2026-06-30/public-poc-released-for-the-libssh2-pre-auth-heap-write-cve
migrated_from: briefs/2026-06-28.md
---

CVE-2026-55200 is a heap out-of-bounds write (CWE-680 integer-overflow-to-buffer-overflow) in libssh2's `ssh2_transport_read()`: the `packet_length` field in an SSH transport packet is not bounds-checked before allocation, so a malicious or compromised SSH **server** can send a crafted length to corrupt a connecting **client's** heap — leading to DoS or, where ASLR is absent, potential remote code execution. NCSC-NL updated advisory NCSC-2026-0210 on 2026-06-24 to note that a public PoC has appeared confirming code execution under specific conditions; the GitHub advisory scores it CVSS 9.2 ([NCSC-NL, 2026-06-24](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0210); [GitHub Advisory GHSA-r8mh-x5qv-7gg2, 2026-06-23](https://github.com/advisories/GHSA-r8mh-x5qv-7gg2)). The companion flaw CVE-2026-55199 (CVSS 8.2, CWE-835 infinite loop via a crafted `SSH_MSG_EXT_INFO` extension count → pre-auth CPU exhaustion/DoS) is also unfixed in 1.11.1. libssh2 is embedded in curl, the PHP ssh2 extension, FileZilla, WinSCP, Bitvise and many network appliances, so downstream exposure depends on vendor uptake. Technique class: `T1190` (client-side, when tricked into connecting to an attacker-controlled server) for the OOB write; `T1499.004` for the DoS. Affected: libssh2 ≤ 1.11.1; fixes are commit `97acf3df` (55200) and `1762685` (55199), with no tagged release (1.11.2) yet. Detection/hardening: hunt heap-corruption crashes in processes using libssh2 (PHP-FPM, curl, scp wrappers); inventory embedded libssh2 versions in appliances/tooling; confirm ASLR is enabled (`/proc/sys/kernel/randomize_va_space` = 2) to raise the bar on the code-execution path; constrain automation hosts to known SSH endpoints.

## Update — 2026-06-30T05:10:41Z

A public proof-of-concept scaffold for CVE-2026-55200 (CVSS 9.2) appeared on 2026-06-29, and no official libssh2 release carrying the fix has been tagged yet — the patch commit was merged to mainline on 2026-06-12 but downstream consumers must build from source or pin manually ([The Hacker News, 2026-06-29](https://thehackernews.com/2026/06/public-poc-released-for-critical.html)).

The flaw is in `ssh2_transport_read()` in `transport.c`, which fails to bound the attacker-controlled `packet_length` field during the SSH transport handshake; a `0xffffffff` value triggers an integer overflow so `malloc` allocates a tiny buffer while the subsequent write fills the full oversized packet, corrupting the heap before authentication ([VulnCheck, 2026-06-17](https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c)). Because libssh2 is the client linked into git, curl, PHP, and many CI/CD runners, a malicious or compromised SSH *server* can corrupt memory in connecting clients — the supply-chain/CI-CD direction is the realistic risk. Pin or rebuild libssh2 from the patched commit in pipeline images now, and surface libssh2 versions through SBOM tooling.
