cbcvebase.
CVE-2026-56855
published 2026-09-02

CVE-2026-56855: Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.38%
31.5th percentile
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.

Affected

216 ranges· showing 25
VendorProductVersion rangeFixed in
advanced-cluster-securityrhacs-main-rhel8——
advanced-cluster-securityrhacs-main-rhel9——
advanced-cluster-securityrhacs-operator-bundle——
advanced-cluster-securityrhacs-rhel8-operator——
advanced-cluster-securityrhacs-rhel9-operator——
advanced-cluster-securityrhacs-roxctl-rhel8——
advanced-cluster-securityrhacs-roxctl-rhel9——
advanced-cluster-securityrhacs-scanner-rhel8——
advanced-cluster-securityrhacs-scanner-rhel9——
advanced-cluster-securityrhacs-scanner-slim-rhel8——
advanced-cluster-securityrhacs-scanner-slim-rhel9——
advanced-cluster-securityrhacs-scanner-v4-rhel8——
advanced-cluster-securityrhacs-scanner-v4-rhel9——
assistedagent-preinstall-image-builder-rhel9——
buildah_projectbuildah——
cert-managerjetstack-cert-manager-acmesolver-rhel9——
cert-managerjetstack-cert-manager-rhel9——
complianceopenshift-security-profiles-operator-bundle——
complianceopenshift-security-profiles-rhel8-operator——
container-native-virtualizationcluster-network-addons-operator——
container-native-virtualizationcluster-network-addons-operator-rhel9——
container-tools_rhel8buildah——
container-tools_rhel8podman——
cryostatcryostat-storage-rhel9——
devspacestraefik-rhel9——

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.