Vulnerabilities

Last updated 49 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
russh Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey Medium Risk 6.5 8 hours ago 8 hours ago
russh russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened High Risk 7.5 9 hours ago 8 hours ago
russh russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic Low Risk 3.7 9 hours ago 8 hours ago
russh Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path Low Risk 3.7 9 hours ago 9 hours ago
russh Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange Medium Risk 4.3 9 hours ago 9 hours ago
russh Russh: Channel-scoped server callbacks can be reached without an open channel Medium Risk 6.5 1 month ago 21 days ago
russh Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Medium Risk 4.3 2 months ago 21 days ago
russh Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Medium Risk 5.3 2 months ago 21 days ago
russh Russh: Unchecked CryptoVec allocation and growth handling is reachable High Risk 7.5 4 months ago 21 days ago
russh-cryptovec Russh: Unchecked CryptoVec allocation and growth handling is reachable High Risk 7.5 4 months ago 21 days ago
russh russh server userauth state is not reset when authentication principal changes Medium Risk 5.3 4 months ago 21 days ago
russh russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler High Risk 7.5 5 months ago 21 days ago
russh Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Medium Risk 5.3 2 months ago 21 days ago
russh russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets High Risk 7.5 4 months ago 21 days ago
russh russh is missing overflow checks during channel windows adjust Medium Risk 6.5 1 year ago 21 days ago
russh Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin Medium Risk 5.9 2 years ago 21 days ago
russh Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds High Risk 7.5 3 months ago 3 months ago
russh Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input Medium Risk 5.3 3 months ago 3 months ago
russh Russh: Unchecked keyboard-interactive prompt count in client auth path Medium Risk 6.5 3 months ago 3 months ago
russh-cryptovec Unchecked `CryptoVec` allocation and growth handling High Risk 7.5 4 months ago 4 months ago
russh Unbounded 32-bit allocation High Risk 7.5 4 months ago 4 months ago
russh Russh has an OOM Denial of Service due to allocation of untrusted amount High Risk 7.5 2 years ago 2 years ago
russh russh may use insecure Diffie-Hellman keys Medium Risk 5.9 3 years ago 2 years ago