Security: Eugeny/russh
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)GHSA-g4mp-vgx3-xrvm published
Sep 3, 2026 by EugenyModerate -
Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekeyGHSA-35g8-35p8-c8fw published
Sep 3, 2026 by EugenyModerate -
russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panicGHSA-p8qx-h547-fjw9 published
Aug 23, 2026 by EugenyLow -
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never openedGHSA-47hw-gvq5-r2gm published
Aug 23, 2026 by EugenyHigh -
Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime pathGHSA-g6xm-f9xp-qq35 published
Aug 11, 2026 by EugenyLow -
Missing X25519 zero-point validation in hybrid ML-KEM key exchangeGHSA-w3jg-pjxf-73p4 published
Aug 21, 2026 by EugenyModerate -
Post-auth remote panic via pty-req with more than 130 terminal-mode recordsGHSA-cqjc-rmpq-xprq published
Jul 22, 2026 by EugenyModerate -
Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)GHSA-5xvq-cp9x-6p6r published
Jul 22, 2026 by EugenyModerate -
client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)GHSA-g9hv-x236-4qp3 published
Jul 22, 2026 by EugenyModerate -
Channel-scoped server callbacks can be reached without an open channel in russhGHSA-m65r-rprj-r5rg published
Jul 31, 2026 by EugenyModerate