๐Ÿ” CVE Alert

CVE-2026-102821

MEDIUM 6.5

Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Russh is a Rust SSH client and server library. Prior to 0.63.2, an authenticated remote peer can send SSH_MSG_KEXINIT without the required SSH_MSG_KEX_ECDH_INIT and then flood SSH_MSG_CHANNEL_OPEN messages while SessionKexState::InProgress prevents priority_receiver in russh/src/server/session.rs from being drained. The server continues processing network input and enqueues a ChannelOpenReply for each request on an unbounded channel, allowing one connection to grow memory until the process is terminated. This issue is fixed in version 0.63.2.

CWE CWE-400 CWE-770
Vendor eugeny
Product russh
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for eugeny russh

Be the first to know when new medium vulnerabilities affecting eugeny russh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Eugeny / russh
< 0.63.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Eugeny/russh/security/advisories/GHSA-35g8-35p8-c8fw github.com: https://github.com/Eugeny/russh/commit/a282af361ac99bc76b80876d1aae128e89dbf66b github.com: https://github.com/Eugeny/russh/releases/tag/v0.63.2