PT-2026-102805 · Russh · Russh

·

CVE-2026-102821

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Russh versions prior to 0.63.2
Description An authenticated remote peer can trigger a memory exhaustion condition by sending SSH MSG KEXINIT without the mandatory SSH MSG KEX ECDH INIT and subsequently flooding SSH MSG CHANNEL OPEN messages. This occurs because SessionKexState::InProgress prevents the priority receiver in russh/src/server/session.rs from being drained. Consequently, the server continues to process network input and enqueues a ChannelOpenReply for every request on an unbounded channel, allowing a single connection to consume memory until the process is terminated.
Recommendations Update to version 0.63.2.

Exploit

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102821
GHSA-35G8-35P8-C8FW

Affected Products

Russh