Memory Flooding Vulnerability in Russh SSH Client and Server Library
CVE-2026-102821

6.5MEDIUM

Key Information:

Vendor

Eugeny

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102821?

The Russh SSH client and server library is vulnerable to a memory flooding issue that arises when an authenticated remote peer sends SSH_MSG_KEXINIT without the necessary SSH_MSG_KEX_ECDH_INIT. This allows the peer to overwhelm the server with an unbounded number of SSH_MSG_CHANNEL_OPEN messages while in the SessionKexState::InProgress state. As a result, the server continues processing these messages, leading to potential memory exhaustion that could crash the process. This vulnerability has been addressed in version 0.63.2.

Affected Version(s)

russh < 0.63.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.