Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.
cvss
0.0
high
severity out of 10
epss
0.00%
medium
chance of exploitation in 30 days, 47th percentile of all CVEs
xyz score
0.0
low
CyberXYZ composite out of 10
fig. 01 — CVE-2026-56855, the advisory selected below
// 1 advisories
CVE-2026-56855
UNKNOWN
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
// cvss v3.1 vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Checked 2026-09-25 at 17:54 UTC. The most recent advisory here was published 2026-09-02. Updated continuously from NVD, GHSA, OSV and CNA feeds.