Vulnerability Bulletins

CVE-2026-59847

   
Affected software OPENSSL
 
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-59847