VYPR
Medium severity5.9NVD Advisory· Published Mar 16, 2023· Updated Jun 17, 2026

CVE-2023-28113

CVE-2023-28113

Description

russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is insufficient, which can lead to insecure shared secrets and therefore breaks confidentiality. Connections between a russh client and server or those of a russh peer with some other misbehaving peer are most likely to be problematic. These may vulnerable to eavesdropping. Most other implementations reject such keys, so this is mainly an interoperability issue in such a case. This issue is fixed in versions 0.36.2 and 0.37.1

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
russhcrates.io
< 0.36.20.36.2
russhcrates.io
>= 0.37.0, < 0.37.10.37.1

Affected products

5
  • cpe:2.3:a:russh_project:russh:*:*:*:*:*:rust:*:*+ 2 more
    • cpe:2.3:a:russh_project:russh:*:*:*:*:*:rust:*:*range: >=0.34.0,<0.36.2
    • cpe:2.3:a:russh_project:russh:0.37.0:-:*:*:*:rust:*:*
    • cpe:2.3:a:russh_project:russh:0.37.0:beta1:*:*:*:rust:*:*
  • ghsa-coords
    Range: < 0.36.2
  • warp-tech/russhv5
    Range: 0.34.0

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.