Vulnerabilities
Vulnerable Software
Russh Project:  >> Russh  >> 0.54.2  Security Vulnerabilities
Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's keyboard-interactive authentication handler. A malicious client can crash any russh-based server that implements keyboard-interactive auth (e.g., for 2FA/TOTP) with a single malformed packet, requiring no credentials. This issue has been patched in version 0.60.1.
CVSS Score
7.5
EPSS Score
0.002
Published
2026-05-08


Contact Us

Shodan ® - All rights reserved