{"id":"CLEANSTART-2026-PN24745","summary":"authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users","details":"Security vulnerability affects the loki package. An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users.","modified":"2026-09-26T05:15:03.701091166Z","published":"2026-09-26T00:38:00.068391Z","upstream":["CVE-2026-39827"],"database_specific":{},"references":[{"type":"ADVISORY","url":"https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-PN24745.json"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-39827"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39827"}],"affected":[{"package":{"name":"loki","ecosystem":"CleanStart"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.7.1-r1"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-PN24745.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}