Medium severity5.9NVD Advisory· Published Mar 16, 2023· Updated Jun 17, 2026
CVE-2023-28113
CVE-2023-28113
Description
russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is insufficient, which can lead to insecure shared secrets and therefore breaks confidentiality. Connections between a russh client and server or those of a russh peer with some other misbehaving peer are most likely to be problematic. These may vulnerable to eavesdropping. Most other implementations reject such keys, so this is mainly an interoperability issue in such a case. This issue is fixed in versions 0.36.2 and 0.37.1
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
russhcrates.io | < 0.36.2 | 0.36.2 |
russhcrates.io | >= 0.37.0, < 0.37.1 | 0.37.1 |
Affected products
5cpe:2.3:a:russh_project:russh:*:*:*:*:*:rust:*:*+ 2 more
- cpe:2.3:a:russh_project:russh:*:*:*:*:*:rust:*:*range: >=0.34.0,<0.36.2
- cpe:2.3:a:russh_project:russh:0.37.0:-:*:*:*:rust:*:*
- cpe:2.3:a:russh_project:russh:0.37.0:beta1:*:*:*:rust:*:*
- warp-tech/russhv5Range: 0.34.0
Patches
Vulnerability mechanics
References
9- github.com/warp-tech/russh/commit/d831a3716d3719dc76f091fcea9d94bd4ef97c6envdPatchWEB
- github.com/warp-tech/russh/security/advisories/GHSA-cqvm-j2r2-hwpgnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-cqvm-j2r2-hwpgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-28113ghsaADVISORY
- github.com/warp-tech/russh/blob/master/russh/src/kex/dh/groups.rsnvdProductWEB
- github.com/warp-tech/russh/blob/master/russh/src/kex/dh/groups.rsnvdProductWEB
- github.com/warp-tech/russh/commit/45d2d82930bf4a675bd57abfafec8fe4065befcdghsaWEB
- github.com/warp-tech/russh/releases/tag/v0.36.2nvdRelease NotesWEB
- github.com/warp-tech/russh/releases/tag/v0.37.1nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.