Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Eugeny — Vulnerabilities & Security Advisories 27

Browse all 27 CVE security advisories affecting Eugeny. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Eugeny is a software component primarily used for data processing and manipulation in enterprise applications. Historically, vulnerabilities in Eugeny have commonly included remote code execution, cross-site scripting, and privilege escalation flaws. The component has been associated with multiple security incidents, including four CVEs that highlight persistent weaknesses in input validation and access controls. Security researchers have noted that Eugeny's architecture often allows for unauthorized system access when proper sanitization measures are not implemented. Organizations using Eugeny should prioritize patching and implement additional validation layers to mitigate risks associated with its historically exploitable vulnerabilities.

Found 19 results / 27 Clear Filters
Top products by Eugeny: russh tabby
CVE ID Title CVSS Severity Published
CVE-2026-102825 Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path — russh CWE-307 3.7 Low 2026-09-29
CVE-2026-102824 Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange — russh CWE-327 4.3 Medium 2026-09-29
CVE-2026-102823 russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened — russh CWE-20 7.5 High 2026-09-29
CVE-2026-102822 russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic — russh CWE-129 3.7 Low 2026-09-29
CVE-2026-102821 Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey — russh CWE-400 6.5 Medium 2026-09-29
CVE-2026-102820 pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows) — russh CWE-125 6.2 Medium 2026-09-29
CVE-2026-73489 Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records — russh CWE-129 4.3 Medium 2026-08-13
CVE-2026-73430 Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) — russh CWE-754 5.3 Medium 2026-08-12
CVE-2026-73429 Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) — russh CWE-704 5.3 Medium 2026-08-12
CVE-2026-68930 Russh: Channel-scoped server callbacks can be reached without an open channel — russh CWE-666 6.5 Medium 2026-08-03
CVE-2026-48110 Russh: SSH message fields were decoded through allocation-first parsers before field-specific bounds — russh CWE-20 7.5 High 2026-06-10
CVE-2026-48108 Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input — russh CWE-20 5.3 Medium 2026-06-10
CVE-2026-48107 Russh: Unchecked keyboard-interactive prompt count in client auth path — russh CWE-20 6.5 Medium 2026-06-10
CVE-2026-46705 russh server userauth state is not reset when authentication principal changes — russh CWE-287 5.3 Medium 2026-06-10
CVE-2026-46702 Russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets — russh CWE-770 7.5 High 2026-06-10
CVE-2026-46673 Russh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releases — russh CWE-770 7.5 High 2026-06-10
CVE-2026-42189 Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth — russh CWE-770 7.5 High 2026-05-08
CVE-2025-54804 Russh is missing an overflow check during channel windows adjust — russh CWE-190 6.5 Medium 2025-08-05
CVE-2024-43410 Russh has an OOM Denial of Service due to allocation of untrusted amount — russh CWE-770 7.5 High 2024-08-21

This page lists every published CVE security advisory associated with Eugeny. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.