<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T16:46:20.651232+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326594</id>
    <title>EUVD-2026-326594</title>
    <updated>2026-10-07T16:46:20.698630+00:00</updated>
    <content>EUVD-2026-326594</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48107</id>
    <title>fkie_cve-2026-48107</title>
    <updated>2026-10-07T16:46:20.698668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Russh is a Rust SSH client &amp; server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_INFO_REQUEST with an attacker-controlled prompt count, and the client would use that raw count directly in Vec::with_capacity(...) before validating that enough prompt data was actually present in the packet. This issue has been patched in version 0.61.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48107"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g9g7-5cgw-6v28</id>
    <title>GHSA-g9g7-5cgw-6v28 — Russh: Unchecked keyboard-interactive prompt count in client auth path</title>
    <updated>2026-10-07T16:46:20.698703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: russh</p>
<p>### Summary
In the `russh` client keyboard-interactive authentication path, a malicious SSH server could send a `USERAUTH_INFO_REQUEST` with an attacker-controlled prompt count, and the client would use that raw count directly in `Vec::with_capacity(...)` before validating that enough prompt data was actually present in the packet.</p>
<p>This is a client-side denial-of-service / resource-exhaustion issue on the keyboard-interactive auth path.</p>
<p>### Details
The vulnerable code path is in:</p>
<p>- `russh/src/client/encrypted.rs`</p>
<p>When the client is in `CurrentRequest::KeyboardInteractive` state and receives `SSH_MSG_USERAUTH_INFO_REQUEST`, it parses:</p>
<p>1. `name`
2. `instructions`
3. `language tag`
4. `n_prompts`</p>
<p>Before the fix, the code then did:</p>
<p>```rust
let n_prompts = map_err!(u32::decode(&amp;mut r))?;
let mut prompts = Vec::with_capacity(n_prompts.try_into().unwrap_or(0));
```</p>
<p>That means a malicious server could advertise an enormous `n_prompts` value even if the packet contained no prompt bodies at all.</p>
<p>The fix rejects inconsistent prompt counts before allocating:</p>
<p>```rust
let n_prompts = map_err!(u32::decode(&amp;mut r))?;
let max_prompts = r.remaining_len() / 5;
let n_prompts = n_prompts as usize;
if n_prompts &gt; max_prompts {
    return Err(crate::Error::Inconsistent.into());
}
let mut prompts = Vec::with_capacity(n_prompts);
```</p>
<p>Each prompt needs at least 4 bytes of string length plus 1 byte of echo flag, so `remaining_len() / 5` is a safe upper bound. If the declared count exceeds w…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g9g7-5cgw-6v28"/>
  </entry>
</feed>
