Low severity3.7NVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-102825
CVE-2026-102825
Description
Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max_auth_attempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment's attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.