SSH Client and Server Library Vulnerability in Russh
CVE-2026-102824
4.3MEDIUM
What is CVE-2026-102824?
The Russh library, a Rust-based SSH client and server, contains an implementation flaw affecting its hybrid key exchange mechanism prior to version 0.63.0. This flaw allows malicious SSH peers to use an all-zero 32-byte X25519 public key, which compromises the integrity of the hybrid key exchange. As a result, the shared secret generated can be manipulated to rely solely on the ML-KEM component, thereby bypassing critical fallbacks designed to enhance security against potential weaknesses in ML-KEM. Users are urged to upgrade to version 0.63.0 or later to mitigate this vulnerability.
Affected Version(s)
russh < 0.63.0
