Medium severity6.5NVD Advisory· Published Aug 3, 2026· Updated Sep 9, 2026
CVE-2026-68930
CVE-2026-68930
Description
Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
russhcrates.io | < 0.62.5 | 0.62.5 |
Affected products
4- osv-coords2 versions
< 26.5.6-r7+ 1 more
- (no CPE)range: < 26.5.6-r7
- (no CPE)range: < 26.5.6-r7
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.