Authentication Bypass Issue in Russh SSH Client and Server Library
CVE-2026-102825

3.7LOW

Key Information:

Vendor

Eugeny

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102825?

The Russh SSH client and server library faced a vulnerability that permits unauthenticated remote clients to submit an unlimited number of authentication requests. This occurs due to the USERAUTH_REQUEST handling in the server's code, which fails to compare the actual number of authentication attempts against a defined maximum. As a result, the deployment's attempt-limiting policy can be circumvented, leading to potential online guessing attacks and increased load on authentication backends. This vulnerability has been resolved in version 0.62.6 of Russh.

Affected Version(s)

russh < 0.62.6

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.