SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-56855

HIGH · CVSS 7.5 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the handling of channel messages, allowing a malicious peer to potentially deadlock the connection by sending crafted messages. The updated implementation now explicitly manages RFC 4254 channel messages and terminates the connection upon encountering unrecognized messages, mitigating the risk of denial of service. Organizations utilizing affected products should prioritize this update to enhance their connection security and prevent service disruptions.

CVE
CVE-2026-56855
Severity
HIGH
CVSS
7.5
EPSS
0.38%

Original NVD Description

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.

Related CVEs

Other vulnerabilities affecting the same vendor(s)