CVE-2026-55200
libssh2 Out-of-Bounds Write Via Unchecked Packet Length in Transport
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A vulnerability in libssh2 allows remote attackers to execute arbitrary code by sending crafted SSH packets with an invalid packet length, leading to heap memory corruption. This could enable attackers to gain control of affected systems. The exposure of this vulnerability depends on whether the affected software is pr