AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73429

MEDIUM · CVSS 5.3 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The russh SSH client and server library is vulnerable to a denial-of-service attack due to improper validation of the server ephemeral value in the KEX_ECDH_REPLY message, which can lead to a client session crash. This vulnerability affects users of Exchange that utilize the russh library prior to version 0.62.4, and it is crucial for organizations relying on this library for SSH communications to prioritize upgrading to the patched version to mitigate potential disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73429
Severity
MEDIUM
CVSS
5.3
EPSS
0.29%
Exchange

Original NVD Description

Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ephemeral value that is not 32 bytes long. The client-side Curve25519Kex::compute_shared_secret function in russh/src/kex/curve25519.rs passes the decoded exchange.server_ephemeral value to clone_from_slice without validating its length, causing a deterministic panic before the server host key is verified. The panic terminates the spawned client session task and surfaces as a JoinError, while the embedding process normally remains running. This issue is fixed in version 0.62.4.