CVE-2026-59847
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 0.33%
- CWE
- CWE-253
- Published
- 2026-07-21
- Last modified
- 2026-09-01
Affected products
- Red Hat Red Hat Hardened Images
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
Weakness type
Related vulnerabilities
- CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
- CVE-2026-5818 — MCU Firmware Update Authentication Bypass on Caliptra Core
- CVE-2026-46419 — Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a...
- CVE-2026-43863 — mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
- CVE-2026-35340 — uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode
- CVE-2026-35339 — uutils coreutils chmod False Success Exit Code in Recursive Mode
- CVE-2026-35091 — Corosync: corosync: denial of service and information disclosure via crafted udp packet
- CVE-2026-0648 — The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in...