๐Ÿ” CVE Alert

CVE-2026-102824

MEDIUM 4.3

Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer X25519 public key in both server_dh and compute_shared_secret, forcing the X25519 contribution to the combined shared secret to zero. A malicious SSH peer can therefore make the combined secret depend only on ML-KEM, defeating the hybrid exchange's intended fallback protection if ML-KEM is later weakened. This issue is fixed in version 0.63.0.

CWE CWE-327
Vendor eugeny
Product russh
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for eugeny russh

Be the first to know when new medium vulnerabilities affecting eugeny russh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Eugeny / russh
< 0.63.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Eugeny/russh/security/advisories/GHSA-w3jg-pjxf-73p4 github.com: https://github.com/Eugeny/russh/commit/8da8967f196472576b1565d518a0ed60fce60f0c github.com: https://github.com/Eugeny/russh/releases/tag/v0.63.0