CVE-2026-48850: Double Free
Published May 25, 2026
·Updated
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
Affected Software
1 affected component
Putty PuTTY>=0.72<0.84
Event History
May 25, 2026
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-48850?
The severity of CVE-2026-48850 is rated as low with a score of 3.7.
2
What is the main issue described in CVE-2026-48850?
CVE-2026-48850 describes a double free vulnerability in the RSA KEX implementation of PuTTY 0.72 before 0.84.
3
How do I fix CVE-2026-48850?
To fix CVE-2026-48850, you should upgrade to PuTTY version 0.84 or later.
4
What software is affected by CVE-2026-48850?
CVE-2026-48850 affects the PuTTY software, specifically versions prior to 0.84.
5
What are the potential impacts of CVE-2026-48850?
The potential impact of CVE-2026-48850 includes denial of service due to the low severity of the vulnerability.