Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-102821: CVE-2026-102821: Unbounded Memory Exhaustion via CHANNEL_OPEN Flood in russh

CVE-2026-102821: Unbounded Memory Exhaustion via CHANNEL_OPEN Flood in russh Vulnerability ID: CVE-2026-102821 CVSS Score: 6.5 Published: 2026-09-30 An uncontrolled resource consumption vulnerability in the russh li

CVE-2026-102821: Unbounded Memory Exhaustion via CHANNEL_OPEN Flood in russh

Vulnerability ID: CVE-2026-102821
CVSS Score: 6.5
Published: 2026-09-30

An uncontrolled resource consumption vulnerability in the russh library allows remote authenticated attackers to exhaust server memory (heap) by flooding channel open requests during a stalled key re-exchange (rekeying) process, causing a denial of service via Out-of-Memory (OOM) termination.

TL;DR

Authenticated remote peers can trigger unbounded memory growth in russh by starting a rekey, stalling the handshake, and flooding connection-layer packets which accumulate in an undrained heap queue.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400
  • Attack Vector: Network (AV:N)
  • CVSS Score: 6.5 (Medium)
  • EPSS Score: 0.00295
  • Exploit Status: No public functional exploit
  • KEV Status: Not listed in CISA KEV
  • Impact: Denial of Service (Memory Exhaustion / Crash)

Affected Systems

  • Applications and services utilizing the russh SSH library prior to version 0.63.2
  • russh: >= 0.58.0, < 0.63.2 (Fixed in: 0.63.2)

Code Analysis

Commit: a282af3

Fix DoS vector by rejecting non-transport messages after KEXINIT

Mitigation Strategies

  • Upgrade the russh dependency to version 0.63.2 or later.
  • Configure aggressive inactivity timeouts on SSH connections.
  • Apply network-layer rate limiting on incoming connection flows.

Remediation Steps:

  1. Open the Cargo.toml file of your project.
  2. Locate the russh dependency and update the version string to '0.63.2' or later.
  3. Execute the command 'cargo update -p russh' in the terminal to update the lockfile.
  4. Rebuild and redeploy the application.

References

Read the full report for CVE-2026-102821 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.