Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f5v4-2wr6-hqmg | russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler |
Thu, 14 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Russh Project
Russh Project russh Warpgate Project Warpgate Project warpgate |
|
| CPEs | cpe:2.3:a:russh_project:russh:*:*:*:*:*:rust:*:* cpe:2.3:a:warpgate_project:warpgate:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Russh Project
Russh Project russh Warpgate Project Warpgate Project warpgate |
Mon, 11 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eugeny
Eugeny russh |
|
| Vendors & Products |
Eugeny
Eugeny russh |
Fri, 08 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's keyboard-interactive authentication handler. A malicious client can crash any russh-based server that implements keyboard-interactive auth (e.g., for 2FA/TOTP) with a single malformed packet, requiring no credentials. This issue has been patched in version 0.60.1. | |
| Title | Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth | |
| Weaknesses | CWE-770 CWE-789 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T14:23:49.308Z
Reserved: 2026-04-25T01:53:21.583Z
Link: CVE-2026-42189
Updated: 2026-05-11T14:23:45.423Z
Status : Analyzed
Published: 2026-05-08T20:16:31.443
Modified: 2026-05-14T18:07:22.943
Link: CVE-2026-42189
No data.
OpenCVE Enrichment
Updated: 2026-05-08T23:00:15Z
Github GHSA