CVE-2026-102825: Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path
Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTHREQUEST path reached from server::runstream in russh/src/server/encrypted.rs increments self.common.authattempts but never compares it with server::Config.maxauthattempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment's attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
russhto a version that resolves this vulnerability.Fixed in 0.62.6
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using Russh as an SSH server are exposed if they run a version prior to 0.62.6 and rely on Config.max_auth_attempts to limit authentication requests. The affected path is reached through server::run_stream.
What does an attacker need to exploit it?
An unauthenticated remote client only needs to be able to connect to the SSH server and submit USERAUTH_REQUEST messages on a single connection. No prior credentials or user interaction are required.
Does this affect the configured authentication-attempt limit?
Yes. Although the runtime path increments the authentication-attempt counter, it does not compare that counter with Config.max_auth_attempts, so the configured cap is not enforced for USERAUTH_REQUEST handling.
How can the issue be remediated?
Update Russh to version 0.62.6, which fixes enforcement of the authentication-attempt cap in the affected path.