Rust SSH Client/Server Library Vulnerability in Russh
CVE-2026-102822

3.7LOW

Key Information:

Vendor

Eugeny

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102822?

Russh, a Rust-based SSH client and server library, allows an attacker to exploit a flaw in the MAC handling mechanism prior to version 0.63.1. When a connection permits mac=none, it incorrectly negotiates with block ciphers that require a MAC. This results in a scenario where a remote peer can trigger a panic by sending a packet with a decrypted length of zero, leading the library to attempt to access a part of the buffer incorrectly, ultimately terminating the connection task. The vulnerability has been addressed in version 0.63.1.

Affected Version(s)

russh < 0.63.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.