Russh Project maintains a focused SSH protocol library whose vulnerability profile centers on resource-handling and cryptographic-validation weaknesses, including allocation exhaustion, improper input validation, and signature-verification gaps. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Russh Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2026-42189HIGH Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's keyboard-interactive authenticatio | May 8, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-54804MEDIUM Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used to track the free space in the receive buff | Aug 5, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-43410HIGH Russh is a Rust SSH client & server library. Allocating an untrusted amount of memory allows any unauthenticated user to OOM a russh server. An SSH packet consists of a 4-byte big- | Aug 21, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-28113MEDIUM russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is insufficient, which can lead to | Mar 16, 2023 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Russh Project.
Media articles that mention a CVE ID that affects a product developed by Russh Project — matched by CVE ID, not by vendor name.