Russh · Russh · CVE-2026-102823
**Name of the Vulnerable Software and Affected Versions**
Russh versions prior to 0.63.1
**Description**
The `client read authenticated` function in `russh/src/client/encrypted.rs` forwards several channel subtypes—including CHANNEL DATA, CHANNEL EXTENDED DATA, CHANNEL EOF, CHANNEL CLOSE, CHANNEL OPEN FAILURE, CHANNEL SUCCESS, CHANNEL FAILURE, and CHANNEL REQUEST (specifically exit-status, exit-signal, and xon-xoff)—to public `client::Handler` callbacks. This occurs without verifying if the `ChannelId` belongs to a channel that the client actually opened and established. Consequently, a malicious SSH server could send lifecycle events for predicted, unopened, unconfirmed, or released channel identifiers, leading to application panics or the corruption of exit-code tracking and command completion.
**Recommendations**
Update to version 0.63.1.