{"id":"CVE-2026-102825","title":"Russh is a Rust SSH client and server library","summary":"Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max…","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-307"],"vendor":"Eugeny","product":"russh","affected":["russh < 0.62.6"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T19:17:24.847","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102825","references":[{"url":"https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653","label":"security-advisories@github.com"},{"url":"https://github.com/Eugeny/russh/releases/tag/v0.62.6","label":"security-advisories@github.com"},{"url":"https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T19:44:04.148Z","slug":"CVE-2026-102825","body":"## Overview\n\nRussh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max_auth_attempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment's attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}