PT-2026-102809 · Russh · Russh
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Russh versions prior to 0.62.6
Description
In the
USERAUTH REQUEST path reached from the server::run stream function in russh/src/server/encrypted.rs, the system increments self.common.auth attempts but fails to compare it against server::Config.max auth attempts. This allows an unauthenticated remote client to submit authentication requests on a single connection beyond the configured limit, bypassing attempt-limiting policies and increasing the potential for online guessing and backend authentication workload.Recommendations
Update to version 0.62.6.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Russh