Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
russh
|
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey | Medium Risk 6.5 | 8 hours ago | 7 hours ago |
russh
|
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened | High Risk 7.5 | 8 hours ago | 8 hours ago |
russh
|
russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic | Low Risk 3.7 | 8 hours ago | 8 hours ago |
russh
|
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path | Low Risk 3.7 | 8 hours ago | 8 hours ago |
russh
|
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange | Medium Risk 4.3 | 8 hours ago | 8 hours ago |
russh
|
Russh: Channel-scoped server callbacks can be reached without an open channel | Medium Risk 6.5 | 1 month ago | 21 days ago |
russh
|
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records | Medium Risk 4.3 | 2 months ago | 21 days ago |
russh
|
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) | Medium Risk 5.3 | 2 months ago | 21 days ago |
russh
|
Russh: Unchecked CryptoVec allocation and growth handling is reachable | High Risk 7.5 | 4 months ago | 21 days ago |
russh-cryptovec
|
Russh: Unchecked CryptoVec allocation and growth handling is reachable | High Risk 7.5 | 4 months ago | 21 days ago |
russh
|
russh server userauth state is not reset when authentication principal changes | Medium Risk 5.3 | 4 months ago | 21 days ago |
russh
|
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler | High Risk 7.5 | 5 months ago | 21 days ago |
russh
|
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) | Medium Risk 5.3 | 2 months ago | 21 days ago |
russh
|
russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets | High Risk 7.5 | 4 months ago | 21 days ago |
russh
|
russh is missing overflow checks during channel windows adjust | Medium Risk 6.5 | 1 year ago | 21 days ago |
russh
|
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin | Medium Risk 5.9 | 2 years ago | 21 days ago |
russh
|
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds | High Risk 7.5 | 3 months ago | 3 months ago |
russh
|
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input | Medium Risk 5.3 | 3 months ago | 3 months ago |
russh
|
Russh: Unchecked keyboard-interactive prompt count in client auth path | Medium Risk 6.5 | 3 months ago | 3 months ago |
russh-cryptovec
|
Unchecked `CryptoVec` allocation and growth handling | High Risk 7.5 | 4 months ago | 4 months ago |
russh
|
Unbounded 32-bit allocation | High Risk 7.5 | 4 months ago | 4 months ago |
russh
|
Russh has an OOM Denial of Service due to allocation of untrusted amount | High Risk 7.5 | 2 years ago | 2 years ago |
russh
|
russh may use insecure Diffie-Hellman keys | Medium Risk 5.9 | 3 years ago | 2 years ago |
Page 1