CVE-2026-55200 (libssh2) Vulnerability Remediation for Layer7 API Gateway 11.2
search cancel

CVE-2026-55200 (libssh2) Vulnerability Remediation for Layer7 API Gateway 11.2

book

Article ID: 447417

calendar_today

Updated On:

Products

CA API Gateway

Issue/Introduction

Security scans have identified that Layer7 API Gateway version 11.2.x is impacted by CVE-2026-55200. This is a critical buffer overflow vulnerability in the libssh2 library (versions 1.11.1 and earlier) within the ssh2_transport_read() function.

Customers requiring compliance with strict security standards may need to remediate this vulnerability urgently to prevent potential remote code execution or denial of service risks.

Environment

  • Product: Layer7 API Gateway
  • Version: 11.2.x (Debian-based)
  • Vulnerable Library: libssh2 versions ≤ 1.11.1

Cause

The vulnerability is caused by a buffer overflow in the underlying libssh2 package included in the Debian distribution used by the API Gateway appliance.

Resolution

Broadcom Engineering will be remediating this vulnerability by updating the libssh2 library in the July 2026 Monthly Platform Package (MPP), which is scheduled for release at the end of July 2026.