MEDIUMVulnerability
CVE-2026-59847
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
Properties
- severity
- MEDIUM
- score
- 5.9
- cve_id
- CVE-2026-59847
- vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- published_at
- 2026-07-21T14:16:34.657
- last_modified
- 2026-08-12T20:17:46.107
Related Entities (8)
AFFECTS_PRODUCT (5)
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
HAS_WEAKNESS (2)
→[Weakness]Incorrect Check of Function Return Value
→[Weakness]
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph