Medium CVE-2026-55200, CVE-2026-84782, CVE-2026-90439 — Three open-source library and server bugs worth patching even though they aren't on CISA's exploited list yet: a libssh2 heap overflow reachable by a malicious SSH server (CVSS 9.2), an OpenSSL DTLS memory disclosure, and an nginx HTTP/3 overflow. Fixed versions for Debian and upstream.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Not every important bug is already being exploited. libssh2 1.11.1 and earlier can be made to corrupt heap memory by a malicious SSH server (CVSS 9.2); it's built into curl, git tools and PHP. OpenSSL's DTLS retransmission can leak heap memory or crash (fixed in 4.0.3 / 3.6.5 / 3.5.9 / 3.4.8). nginx HTTP/3 with OpenSSL ≤ 3.5.0 has a limited heap overflow (fixed in 1.31.6 / 1.30.5). None are on CISA's KEV list as of October 8, 2026.
| CVE-2026-55200 | libssh2 ≤ 1.11.1: unchecked packet_length in ssh2_transport_read() → heap overflow → possible RCE. CVSS 4.0: 9.2. No upstream release yet; fixed in commit 97acf3df |
|---|---|
| CVE-2026-84782 | OpenSSL DTLS retransmit reads from a stale buffer offset → heap disclosure or crash. Fixed 4.0.3, 3.6.5, 3.5.9, 3.4.8 (advisory 2026-09-29) |
| CVE-2026-90439 | nginx ngx_http_v3_module with OpenSSL ≤ 3.5.0: limited heap overflow during TLS handshake → worker restart. CVSS 6.5. Fixed 1.31.6 / 1.30.5 |
| Exploited? | No known exploitation (not on CISA KEV as of 2026-10-08) |
libssh2 is a client-side SSH library. It’s what curl/libcurl commonly uses for sftp:// and scp://, what libgit2-based tools use for SSH remotes, and what PHP’s ssh2 extension wraps. In 1.11.1 and earlier, ssh2_transport_read() trusts the packet_length field from the other side, so a malicious or compromised SSH server can send an oversized length and corrupt heap memory in the client, potentially leading to code execution.
Who’s at risk: anything that connects with libssh2 to SSH servers you don’t fully control, such as backup jobs that SFTP to third-party storage, CI that clones over SSH, or apps that let users enter an SFTP URL.
libssh2-1t64 1.11.1-1+deb13u1 (DSA-6365-1).97acf3df (PR #2052). Projects that bundle libssh2 (some curl builds, Windows tools) need to rebuild with it.dpkg -l | grep libssh2
curl -V | grep -o 'libssh2/[0-9.]*'
DTLS is TLS over UDP, used by some VPNs (including several SSL-VPN clients), WebRTC and IoT protocols. When a handshake-message write is suspended part-way and later retransmitted, OpenSSL reads past the message buffer, sending heap memory to the peer as plaintext handshake data or crashing if it hits unmapped memory. Plain TLS over TCP (HTTPS, most servers) isn’t affected.
| Branch | Fixed |
|---|---|
| 4.0 | 4.0.3 |
| 3.6 | 3.6.5 |
| 3.5 (LTS) | 3.5.9 · Debian 13: 3.5.7-1~deb13u3 (DSA-6531-1) |
| 3.4 | 3.4.8 |
| 3.0 (LTS), 1.1.1 | Listed as affected; check the OpenSSL advisory and your distro (Debian 12 had no fix yet when this was written) |
openssl version
With HTTP/3 enabled (listen 443 quic;) and nginx built against OpenSSL 3.5.0 or older, a limited heap overflow can happen while processing a TLS handshake, non-deterministically, causing worker restarts and limited data corruption. Affects nginx 1.29.2–1.31.5 and 1.30.4. Fixed in 1.31.6 and 1.30.5. If you don’t use HTTP/3, you’re not exposed. See our nginx CVE-2026-42533 advisory for the more serious nginx bug this year.
nginx -V 2>&1 | grep -oE 'nginx/[0-9.]+|OpenSSL [0-9.]+[a-z]*'
nginx -T 2>/dev/null | grep -n 'quic'
# Debian / Ubuntu
apt update && apt full-upgrade
# restart services that load these libraries (or reboot):
needrestart -r a
Library updates only take effect when the programs using them restart. needrestart (Debian/Ubuntu) or dnf needs-restarting -s (RHEL) lists what still has the old version loaded.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.