CVE-2026-58317
CVE-2026-58317 is a medium-severity vulnerability with a CVSS 3.x base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-196.
Key facts
- Severity: Medium (CVSS 3.x base score 6.3)
- CVSS v4: 5.1
- EPSS exploit prediction: 0% (25th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-196
- Published:
- Last modified:
Description
Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
Frequently asked questions
- What is CVE-2026-58317?
- Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
- How severe is CVE-2026-58317?
- CVE-2026-58317 has a CVSS 3.x base score of 6.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-58317 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (25th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-58317?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-58317 published?
- CVE-2026-58317 was published on 2026-07-17.
References
- https://jvn.jp/en/jp/JVN65294474/
- https://teratermproject.github.io/SA/JVN65294474-en.html
- https://teratermproject.github.io/SA/JVN65294474.html
Other CWE-196 vulnerabilities
- CVE-2026-14454 — Critical (CVSS 9.8): Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD…
- CVE-2026-93019 — Critical (CVSS 9.1): Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in…
- CVE-2026-34155 — Medium (CVSS 5.3): RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain'…