PT-2026-48545 · Eugeny · Russh
Published
2026-06-10
·
Updated
2026-06-10
·
CVE-2026-48107
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH INFO REQUEST with an attacker-controlled prompt count, and the client would use that raw count directly in Vec::with capacity(...) before validating that enough prompt data was actually present in the packet. This issue has been patched in version 0.61.0.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Russh