Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

russh — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in russh, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with the russh SSH server implementation, a popular Rust-based alternative to OpenSSH. It aggregates security data from various sources to provide a comprehensive view of the known flaws affecting this specific software product. The content collected here spans from the initial public releases of russh through the most recent updates, ensuring that users have access to historical context as well as current threat intelligence. By reviewing this aggregation, you can track vendor advisories related to russh, allowing you to stay informed about critical patches and security updates released by the maintainers. You can also gain a deeper understanding of common weakness classes identified in this codebase, such as improper input validation or cryptographic implementation errors, which helps in assessing the overall security posture of the software. Furthermore, this resource enables you to look up the product's vulnerability history, providing a timeline of when specific issues were reported and resolved. This chronological perspective is essential for risk assessment and helps organizations determine if they are using versions that are susceptible to known exploits. The page serves as a centralized reference point for security researchers, system administrators, and developers who need to evaluate the safety of using russh in their infrastructure. It does not replace official vendor statements but complements them by organizing disparate reports into a coherent structure. This approach facilitates better decision-making regarding upgrade paths and mitigation strategies. Ultimately, the goal is to enhance transparency and improve the security awareness surrounding the russh project by making vulnerability data easily accessible and analyzable for all stakeholders involved in its deployment and maintenance.

Vendor: warp-tech

CVE IDTitleCVSSSeverityPublished
CVE-2026-73489 Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records CWE-129 4.3 Medium2026-08-13
CVE-2026-73430 Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) CWE-754 5.3 Medium2026-08-12
CVE-2026-73429 Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) CWE-704 5.3 Medium2026-08-12
CVE-2026-68930 Russh: Channel-scoped server callbacks can be reached without an open channel CWE-666 6.5 Medium2026-08-03
CVE-2026-48110 Russh: SSH message fields were decoded through allocation-first parsers before field-specific bounds CWE-20 7.5 High2026-06-10
CVE-2026-48108 Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input CWE-20 5.3 Medium2026-06-10
CVE-2026-48107 Russh: Unchecked keyboard-interactive prompt count in client auth path CWE-20 6.5 Medium2026-06-10
CVE-2026-46705 russh server userauth state is not reset when authentication principal changes CWE-287 5.3 Medium2026-06-10
CVE-2026-46702 Russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets CWE-770 7.5 High2026-06-10
CVE-2026-46673 Russh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releases CWE-770 7.5 High2026-06-10
CVE-2026-42189 Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth CWE-770 7.5 High2026-05-08
CVE-2025-54804 Russh is missing an overflow check during channel windows adjust CWE-190 6.5 Medium2025-08-05
CVE-2024-43410 Russh has an OOM Denial of Service due to allocation of untrusted amount CWE-770 7.5 High2024-08-21
CVE-2023-28113 russh may use insecure Diffie-Hellman keys CWE-20 5.9 Medium2023-03-16

All 14 known CVE vulnerabilities affecting russh with full Chinese analysis, references, and POCs where available.