๐Ÿ” CVE Alert

CVE-2026-102823

HIGH 7.5

russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and CHANNEL_REQUEST subtypes exit-status, exit-signal, and xon-xoff to public client::Handler callbacks without confirming that the ChannelId belongs to a channel the client opened and established. A malicious SSH server can send lifecycle events for predicted, unopened, unconfirmed, or released channel identifiers, causing application panics or corrupting command completion and exit-code tracking. This issue is fixed in version 0.63.1.

CWE CWE-20
Vendor eugeny
Product russh
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for eugeny russh

Be the first to know when new high vulnerabilities affecting eugeny russh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Eugeny / russh
< 0.63.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Eugeny/russh/security/advisories/GHSA-47hw-gvq5-r2gm github.com: https://github.com/Eugeny/russh/commit/3430fd26ecafc0dc3705210f5f39a9119fa22774 github.com: https://github.com/Eugeny/russh/releases/tag/v0.63.1