← Vulnerability feed

Vulnerability record · CVE-2026-42189 · published 8 May 2026

CVE-2026-42189: Russh project russh allocation without limits vulnerability

Russh Project · Russh

Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's keyboard-interactive authentication handler. A malicious client can crash any russh-based server that implements keyboard-interactive auth (e.g., for 2FA/TOTP) with a single malformed packet, requiring no credentials. This issue has been patched in version 0.60.1.

7.5 CVSS 3.1 High EPSS 0.76% · top 46.6% CWE-770 · Allocation without limitsCWE-789 · CWE-789
7.5CVSS 3.1 base score
0.76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's keyboard-interactive authentication handler. A malicious client can crash any russh-based server that implements keyboard-interactive auth (e.g., for 2FA/TOTP) with a single malformed packet, requiring no credentials. This issue has been patched in version 0.60.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-42189 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-48712Warpgate project warpgate incorrect authorization vulnerabilityWarpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. In affected versions there is a privilege escalation vulnerability through a …EPSS 0.68%8.8CVE-2023-37268Warpgate project warpgate improper authentication vulnerabilityWarpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a user with SSO enabled an attac…EPSS 0.55%8.1CVE-2023-43660Warpgate project warpgate improper authentication vulnerabilityWarpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be byp…EPSS 0.25%7.5CVE-2024-43410Russh project russh allocation without limits vulnerabilityRussh is a Rust SSH client & server library. Allocating an untrusted amount of memory allows any unauthenticated user to OOM a russh server. An SSH p…EPSS 0.91%6.5CVE-2026-44347Warpgate project warpgate cross-site request forgery vulnerabilityWarpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which ma…EPSS 0.16%6.5CVE-2025-54804Russh project russh integer overflow vulnerabilityRussh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used to track the…EPSS 0.40%5.9CVE-2023-48795SSH Terrapin attack downgrades channel integrity in OpenSSH and many SSH implementationsThe SSH transport protocol with certain OpenSSH extensions mishandles the handshake and sequence numbers, letting a remote attacker omit packets from…EPSS 93%analysed5.9CVE-2023-28113Russh project russh improper input validation vulnerabilityrussh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is i…EPSS 0.64%

Source: NIST National Vulnerability Database (record CVE-2026-42189), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.