CVE-2026-102825 Details
Description
Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max_auth_attempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment's attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6.
A vulnerability in the Russh SSH client and server library, prior to version 0.62.6, allows an unauthenticated remote client to bypass the configured authentication attempt limit. The issue arises because the library's USERAUTH_REQUEST handling increments the authentication attempt counter without checking it against the maximum allowed attempts. This flaw enables clients to send more authentication requests than permitted, increasing the risk of online password guessing attacks and adding unnecessary load to the backend authentication system.
Users can update to Russh version 0.62.6 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35 | CISA-ADP | AdvisoryExploitRemedyTechnical AnalysisVendor |
| https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653 | [email protected] | Source CodeVendor |
| https://github.com/Eugeny/russh/releases/tag/v0.62.6 | [email protected] | Release NotesVendor |
| https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35 | [email protected] | AdvisoryExploitRemedyTechnical AnalysisVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eugeny russh | <= 0.62.5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion