Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

libssh2 CVE-2026-55200 (RCE), OpenSSL DTLS CVE-2026-84782, nginx HTTP/3 CVE-2026-90439: Library Bugs to Patch

Medium CVE-2026-55200, CVE-2026-84782, CVE-2026-90439 — Three open-source library and server bugs worth patching even though they aren't on CISA's exploited list yet: a libssh2 heap overflow reachable by a malicious SSH server (CVSS 9.2), an OpenSSL DTLS memory disclosure, and an nginx HTTP/3 overflow. Fixed versions for Debian and upstream.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Not every important bug is already being exploited. libssh2 1.11.1 and earlier can be made to corrupt heap memory by a malicious SSH server (CVSS 9.2); it's built into curl, git tools and PHP. OpenSSL's DTLS retransmission can leak heap memory or crash (fixed in 4.0.3 / 3.6.5 / 3.5.9 / 3.4.8). nginx HTTP/3 with OpenSSL ≤ 3.5.0 has a limited heap overflow (fixed in 1.31.6 / 1.30.5). None are on CISA's KEV list as of October 8, 2026.

CVE-2026-55200libssh2 ≤ 1.11.1: unchecked packet_length in ssh2_transport_read() → heap overflow → possible RCE. CVSS 4.0: 9.2. No upstream release yet; fixed in commit 97acf3df
CVE-2026-84782OpenSSL DTLS retransmit reads from a stale buffer offset → heap disclosure or crash. Fixed 4.0.3, 3.6.5, 3.5.9, 3.4.8 (advisory 2026-09-29)
CVE-2026-90439nginx ngx_http_v3_module with OpenSSL ≤ 3.5.0: limited heap overflow during TLS handshake → worker restart. CVSS 6.5. Fixed 1.31.6 / 1.30.5
Exploited?No known exploitation (not on CISA KEV as of 2026-10-08)

libssh2: CVE-2026-55200

libssh2 is a client-side SSH library. It’s what curl/libcurl commonly uses for sftp:// and scp://, what libgit2-based tools use for SSH remotes, and what PHP’s ssh2 extension wraps. In 1.11.1 and earlier, ssh2_transport_read() trusts the packet_length field from the other side, so a malicious or compromised SSH server can send an oversized length and corrupt heap memory in the client, potentially leading to code execution.

Who’s at risk: anything that connects with libssh2 to SSH servers you don’t fully control, such as backup jobs that SFTP to third-party storage, CI that clones over SSH, or apps that let users enter an SFTP URL.

  • Debian 12: not affected (ships 1.10.0, which predates the bug).
  • Debian 13: fixed in libssh2-1t64 1.11.1-1+deb13u1 (DSA-6365-1).
  • Upstream: no new release as of this writing; the fix is commit 97acf3df (PR #2052). Projects that bundle libssh2 (some curl builds, Windows tools) need to rebuild with it.
dpkg -l | grep libssh2
curl -V | grep -o 'libssh2/[0-9.]*'

OpenSSL: CVE-2026-84782 (DTLS)

DTLS is TLS over UDP, used by some VPNs (including several SSL-VPN clients), WebRTC and IoT protocols. When a handshake-message write is suspended part-way and later retransmitted, OpenSSL reads past the message buffer, sending heap memory to the peer as plaintext handshake data or crashing if it hits unmapped memory. Plain TLS over TCP (HTTPS, most servers) isn’t affected.

BranchFixed
4.04.0.3
3.63.6.5
3.5 (LTS)3.5.9 · Debian 13: 3.5.7-1~deb13u3 (DSA-6531-1)
3.43.4.8
3.0 (LTS), 1.1.1Listed as affected; check the OpenSSL advisory and your distro (Debian 12 had no fix yet when this was written)
openssl version

nginx: CVE-2026-90439 (HTTP/3)

With HTTP/3 enabled (listen 443 quic;) and nginx built against OpenSSL 3.5.0 or older, a limited heap overflow can happen while processing a TLS handshake, non-deterministically, causing worker restarts and limited data corruption. Affects nginx 1.29.2–1.31.5 and 1.30.4. Fixed in 1.31.6 and 1.30.5. If you don’t use HTTP/3, you’re not exposed. See our nginx CVE-2026-42533 advisory for the more serious nginx bug this year.

nginx -V 2>&1 | grep -oE 'nginx/[0-9.]+|OpenSSL [0-9.]+[a-z]*'
nginx -T 2>/dev/null | grep -n 'quic'

How to patch

# Debian / Ubuntu
apt update && apt full-upgrade
# restart services that load these libraries (or reboot):
needrestart -r a

Library updates only take effect when the programs using them restart. needrestart (Debian/Ubuntu) or dnf needs-restarting -s (RHEL) lists what still has the old version loaded.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories