{"id":"CVE-2026-48110","aliases":["GHSA-4r3c-5hpg-58qr"],"url":"https://o3.security/vulnerability/CVE-2026-48110","summary":"Russh: SSH message fields were decoded through allocation-first parsers before field-specific bounds","details":"Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded attacker-controlled SSH strings, name-lists, and byte fields into owned allocations before applying field-specific bounds. A remote SSH peer could send oversized, high-fanout, or malformed length-prefixed fields and make the library allocate, attempt to allocate, or split data before rejecting input that should have been rejected earlier. This issue has been patched in version 0.61.0.","published":"2026-06-10T20:26:29.994Z","modified":"2026-08-12T03:51:48.435881108Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00367,"percentile":0.29356,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"russh","fixedVersion":"0.61.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48110.json"},{"type":"ADVISORY","url":"https://github.com/Eugeny/russh/security/advisories/GHSA-4r3c-5hpg-58qr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48110"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.435881108Z"}}