Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Eugeny — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting Eugeny. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Eugeny is a software component primarily used for data processing and manipulation in enterprise applications. Historically, vulnerabilities in Eugeny have commonly included remote code execution, cross-site scripting, and privilege escalation flaws. The component has been associated with multiple security incidents, including four CVEs that highlight persistent weaknesses in input validation and access controls. Security researchers have noted that Eugeny's architecture often allows for unauthorized system access when proper sanitization measures are not implemented. Organizations using Eugeny should prioritize patching and implement additional validation layers to mitigate risks associated with its historically exploitable vulnerabilities.

Top products by Eugeny: russh tabby
CVE IDTitleCVSSSeverityPublished
CVE-2026-73489 Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records — russhCWE-129 4.3 Medium2026-08-13
CVE-2026-73430 Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) — russhCWE-754 5.3 Medium2026-08-12
CVE-2026-73429 Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) — russhCWE-704 5.3 Medium2026-08-12
CVE-2026-72903 Tabby: Windows SFTP path traversal allows a malicious server to write files outside the selected download directory — tabbyCWE-22 8.1 High2026-08-10
CVE-2026-68930 Russh: Channel-scoped server callbacks can be reached without an open channel — russhCWE-666 6.5 Medium2026-08-03
CVE-2026-46709 Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038) — tabbyCWE-77 7.8 High2026-07-15
CVE-2026-48110 Russh: SSH message fields were decoded through allocation-first parsers before field-specific bounds — russhCWE-20 7.5 High2026-06-10
CVE-2026-48108 Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input — russhCWE-20 5.3 Medium2026-06-10
CVE-2026-48107 Russh: Unchecked keyboard-interactive prompt count in client auth path — russhCWE-20 6.5 Medium2026-06-10
CVE-2026-46705 russh server userauth state is not reset when authentication principal changes — russhCWE-287 5.3 Medium2026-06-10
CVE-2026-46702 Russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets — russhCWE-770 7.5 High2026-06-10
CVE-2026-46673 Russh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releases — russhCWE-770 7.5 High2026-06-10
CVE-2026-45038 Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution — tabbyCWE-150--2026-05-15
CVE-2026-45036 Tabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zsh — tabbyCWE-78 7.0 High2026-05-15
CVE-2026-45035 Tabby: RCE via `tabby://run` URL Scheme — tabbyCWE-78--2026-05-15
CVE-2026-45037 Tabby: Unsafe protocol handler execution via terminal linkifier allows arbitrary OS protocol invocation — tabbyCWE-184 7.1 High2026-05-15
CVE-2026-42189 Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth — russhCWE-770 7.5 High2026-05-08
CVE-2025-54804 Russh is missing an overflow check during channel windows adjust — russhCWE-190 6.5 Medium2025-08-05
CVE-2025-22136 Tabby has a TCC Bypass via Misconfigured Node Fuses — tabbyCWE-94 7.8 -2025-01-08
CVE-2024-55950 Tabby has a TCC Bypass via Unnecessary Permissive Entitlements in Tabby — tabbyCWE-276 6.6 -2024-12-26
CVE-2024-43410 Russh has an OOM Denial of Service due to allocation of untrusted amount — russhCWE-770 7.5 High2024-08-21

This page lists every published CVE security advisory associated with Eugeny. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.