Medium severity6.5NVD Advisory· Published Jun 10, 2026· Updated Jun 11, 2026
CVE-2026-48107
CVE-2026-48107
Description
Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_INFO_REQUEST with an attacker-controlled prompt count, and the client would use that raw count directly in Vec::with_capacity(...) before validating that enough prompt data was actually present in the packet. This issue has been patched in version 0.61.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
russhcrates.io | >= 0.37.0, < 0.61.0 | 0.61.0 |
Affected products
3Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.