Package impact
crates.io / russh
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-46673 | high | — | 8.0 | 9d ago | Russh: Unchecked CryptoVec allocation and growth handling is reachable | |||
| CVE-2026-42189 | high | 7.5 | 7.5 | 22d ago | russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler | |||
| CVE-2023-48795 | medium | 5.9 | 5.9 | 3y ago | RHSA-2024:2988: container-tools:rhel8 security update (Moderate) | |||
| CVE-2026-46705 | unknown | — | — | 21h ago | russh server userauth state is not reset when authentication principal changes | |||
| CVE-2026-46702 | unknown | — | — | 21h ago | russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets |