CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-26466

Medium · CVSS 5.9

OpenSSH — Pre-authentication denial of service via uncontrolled memory allocation (ping/pong packet queue exhaustion)

CVSS
5.9
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-770, CWE-770

Description

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

Search profile — drives PoC discovery

Symbols SSH_MSG_PINGSSH_MSG_PONGssh_packet_send_debugsshbuf_allocatepingpongkey exchangekexpacket queuesshbufdispatch_setssh_dispatch_run
Keywords CVE-2025-26466OpenSSH DoSSSH ping pong memory exhaustionpre-authentication DoS OpenSSHSSH packet queue memory leakOpenSSH CWE-770OpenSSH uncontrolled memory consumptionOpenSSH key exchange DoSQualys OpenSSH 2025openssh-mitm-dos
Versions: OpenSSH versions affected prior to patch for CVE-2025-26466

Ranked PoCs (11) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z