PT-2026-102809 · Russh · Russh

·

CVE-2026-102825

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Russh versions prior to 0.62.6
Description In the USERAUTH REQUEST path reached from the server::run stream function in russh/src/server/encrypted.rs, the system increments self.common.auth attempts but fails to compare it against server::Config.max auth attempts. This allows an unauthenticated remote client to submit authentication requests on a single connection beyond the configured limit, bypassing attempt-limiting policies and increasing the potential for online guessing and backend authentication workload.
Recommendations Update to version 0.62.6.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102825
GHSA-G6XM-F9XP-QQ35

Affected Products

Russh