Authentication Bypass Issue in Russh SSH Client and Server Library
CVE-2026-102825
3.7LOW
What is CVE-2026-102825?
The Russh SSH client and server library faced a vulnerability that permits unauthenticated remote clients to submit an unlimited number of authentication requests. This occurs due to the USERAUTH_REQUEST handling in the server's code, which fails to compare the actual number of authentication attempts against a defined maximum. As a result, the deployment's attempt-limiting policy can be circumvented, leading to potential online guessing attacks and increased load on authentication backends. This vulnerability has been resolved in version 0.62.6 of Russh.
Affected Version(s)
russh < 0.62.6
