VYPR
Medium severity6.5NVD Advisory· Published Jun 10, 2026· Updated Jun 11, 2026

CVE-2026-48107

CVE-2026-48107

Description

Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_INFO_REQUEST with an attacker-controlled prompt count, and the client would use that raw count directly in Vec::with_capacity(...) before validating that enough prompt data was actually present in the packet. This issue has been patched in version 0.61.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
russhcrates.io
>= 0.37.0, < 0.61.00.61.0

Affected products

3
  • Eugeny/Russhinferred2 versions
    >=0.37.0,<0.61.0+ 1 more
    • (no CPE)range: >=0.37.0,<0.61.0
    • (no CPE)range: >=0.37.0 <0.61.0
  • ghsa-coords
    Range: >= 0.37.0, < 0.61.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.