Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g9hv-x236-4qp3 | Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) |
Wed, 12 Aug 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eugeny
Eugeny russh |
|
| Vendors & Products |
Eugeny
Eugeny russh |
Wed, 12 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ephemeral value that is not 32 bytes long. The client-side Curve25519Kex::compute_shared_secret function in russh/src/kex/curve25519.rs passes the decoded exchange.server_ephemeral value to clone_from_slice without validating its length, causing a deterministic panic before the server host key is verified. The panic terminates the spawned client session task and surfaces as a JoinError, while the embedding process normally remains running. This issue is fixed in version 0.62.4. | |
| Title | Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) | |
| Weaknesses | CWE-704 CWE-754 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T20:53:19.558Z
Reserved: 2026-08-12T14:32:11.796Z
Link: CVE-2026-73429
No data.
Status : Received
Published: 2026-08-12T21:17:41.750
Modified: 2026-08-12T21:17:41.750
Link: CVE-2026-73429
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:00:05Z
Github GHSA