Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

russh — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in russh, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Russh product, a Rust-based SSH client and server library, categorized under the software weakness tag of remote code execution. It collects records of reported security flaws affecting this specific implementation, covering the period from 2024 to the present. Readers can use this section to track the vendor's advisory history, understand the specific weakness classes associated with the library, and review the chronological vulnerability record to assess risk and patching needs. The data serves as a reference point for security engineers and developers integrating Russh into their applications, providing a consolidated view of known issues without requiring navigation across multiple external databases.

Vendor: warp-tech

CVE ID Title CVSS Severity Published
CVE-2026-102825 Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path CWE-307 3.7 Low 2026-09-29
CVE-2026-102824 Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange CWE-327 4.3 Medium 2026-09-29
CVE-2026-102823 russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened CWE-20 7.5 High 2026-09-29
CVE-2026-102822 russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic CWE-129 3.7 Low 2026-09-29
CVE-2026-102821 Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey CWE-400 6.5 Medium 2026-09-29
CVE-2026-102820 pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows) CWE-125 6.2 Medium 2026-09-29
CVE-2026-73489 Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records CWE-129 4.3 Medium 2026-08-13
CVE-2026-73430 Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) CWE-754 5.3 Medium 2026-08-12
CVE-2026-73429 Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) CWE-704 5.3 Medium 2026-08-12
CVE-2026-68930 Russh: Channel-scoped server callbacks can be reached without an open channel CWE-666 6.5 Medium 2026-08-03
CVE-2026-48110 Russh: SSH message fields were decoded through allocation-first parsers before field-specific bounds CWE-20 7.5 High 2026-06-10
CVE-2026-48108 Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input CWE-20 5.3 Medium 2026-06-10
CVE-2026-48107 Russh: Unchecked keyboard-interactive prompt count in client auth path CWE-20 6.5 Medium 2026-06-10
CVE-2026-46705 russh server userauth state is not reset when authentication principal changes CWE-287 5.3 Medium 2026-06-10
CVE-2026-46702 Russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets CWE-770 7.5 High 2026-06-10
CVE-2026-46673 Russh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releases CWE-770 7.5 High 2026-06-10
CVE-2026-42189 Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth CWE-770 7.5 High 2026-05-08
CVE-2025-54804 Russh is missing an overflow check during channel windows adjust CWE-190 6.5 Medium 2025-08-05
CVE-2024-43410 Russh has an OOM Denial of Service due to allocation of untrusted amount CWE-770 7.5 High 2024-08-21
CVE-2023-28113 russh may use insecure Diffie-Hellman keys CWE-20 5.9 Medium 2023-03-16

All 20 known CVE vulnerabilities affecting russh with full Chinese analysis, references, and POCs where available.