https://app.opencve.io/cve/CVE-2026-55200 is a memory corruption in libssh2 that potentially allows a remote attacker who controls an SSH server to execute arbitrary code on clients who connect to it.
In VyOS, it's used by curl, which we use for commit archive over SSH and for tech support report uploads.
It's difficult to exploit and exploits have to be tailored to applications, but the main point is that Debian still lacks a fix and we have to produce a patched version ourselves if we want it fixes, for now at least.