CVE-2026-102825: low-severity vulnerability in Eugeny russh
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.7epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max_auth_attempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment's attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Eugeny · russhRelated CVEs — Eugeny russh
In the same product, most dangerous first.
CVE-2024-43410HIGHRussh has an OOM Denial of Service due to allocation of untrusted amountEPSS 0.9%CVE-2026-42189HIGHRussh: Pre-auth DoS via unbounded allocation in keyboard-interactive authEPSS 0.8%CVE-2026-73430MEDIUMRussh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)EPSS 0.6%CVE-2026-73429MEDIUMRussh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)EPSS 0.5%CVE-2026-48108MEDIUMRussh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner inputEPSS 0.5%CVE-2026-48110HIGHRussh: SSH message fields were decoded through allocation-first parsers before field-specific boundsEPSS 0.5%