Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needs_mac() only when MAC selection fails. A remote p
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102823 | 7.5 HIGH | russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never |
| CVE-2026-102821 | 6.5 MEDIUM | Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey |
| CVE-2026-102820 | 6.2 MEDIUM | pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a mali |
| CVE-2026-102824 | 4.3 MEDIUM | Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange |
| CVE-2026-102825 | 3.7 LOW | Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime |
No comments yet