Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🦀
🦀 crates.io
Not in CISA KEV
MEDIUM severity

CVE-2026-73429 — russh

MEDIUMFix: Eugeny/russh@a7fc1eb

CVE-2026-73429 is a medium-severity (CVSS 5.3) CWE-704 vulnerability in russh. A fix is available for russh — see the affected versions and patch details below.

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Also known asGHSA-g9hv-x236-4qp3
Published
Aug 12, 2026
Updated
Sep 11, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 26, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-73429.

EPSS Exploitation Probability

via FIRST.org ↗
0.5%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs41th percentile — riskier than 41% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2026-73429 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 379,842 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

1 pkg affected
🦀russh

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects crates.io packages — download data is not available via public APIs for these ecosystems.

Description

Summary

A malicious SSH server can crash a russh client session with a single malformed key-exchange reply, causing a pre-authentication Denial-of-Service before the server host key is verified. The embedding process itself stays up, but the connection is killed deterministically.

Details

Every other kex path in russh validates the peer ephemeral length before cloning:

  • Curve25519Kex::server_dh (russh/src/kex/curve25519.rs:61-65) checks if pubkey_len != 32 { return Err(crate::Error::Kex); } before clone_from_slice.
  • The hybrid ML-KEM, ECDH-NIST, and DH/GEX paths all validate lengths.

Only the client-side curve25519 compute_shared_secret is missing the check. This asymmetric validation gap makes the bug easy to miss in code review: a malicious client cannot panic a russh server this way (the server path checks the length), but a malicious server can panic a russh client.

Incriminated source code (repo-relative paths):

  • Vulnerable compute_shared_secret: russh/src/kex/curve25519.rs:110-117 (panic at line 113)
  • Client-side entry point: russh/src/client/kex.rs:266-277 (KEX_ECDH_REPLY → Bytes::decode → compute_shared_secret)
  • Server-side contrast (has the length check): russh/src/kex/curve25519.rs:51-88 (server_dh)
  • Session spawn site: russh/src/client/mod.rs (connect_stream → russh_util::runtime::spawn)
  • Runtime wrapper: russh-util/src/runtime.rs:37-48 (spawn wraps tokio::spawn; panic surfaces as JoinError)

PoC

A standalone, self-contained Cargo PoC is provided in vuln_poc/vuln_002_client_wronglen_x25519_panic/ in this repo. It installs a global panic hook that sets an AtomicBool if any panic fires, starts a malicious raw SSH server on 127.0.0.1:0 that completes the SSH id and KEXINIT exchange, reads the client KEX_ECDH_INIT, and sends KEX_ECDH_REPLY with a 16-byte server ephemeral (instead of 32) and a fake signature. It then calls russh::client::connect with Preferred::kex set to curve25519-sha256 and a handler that accepts any server key (the check is never reached because the client panics first) and prints a clear verdict.

Build & run:

cd vuln_poc/vuln_002_client_wronglen_x25519_panic
cargo run --release

Expected output (verdict line, from a successful reproduction):

[poc] panic captured: panicked at russh/src/kex/curve25519.rs:113:25:
  copy_from_slice: source slice length (16) does not match destination slice length (32)
[!] Vulnerability reproduced: russh client panicked in Curve25519Kex::compute_shared_secret
  on a wrong-length (16-byte) server ephemeral before verifying the host key signature
  (pre-auth client DoS).

The malicious payload is the f field of KEX_ECDH_REPLY:

MSG_KEX_ECDH_REPLY (1 byte, value 0x1f)
  string K_S            (server host key blob — any valid-looking bytes)
  string f              (server ephemeral — 16 bytes of 0x00 instead of 32)
  string signature      (fake; never verified by the client)

The length prefix of f is 4 (u32 BE) = 16, followed by 16 bytes. The russh client decodes this into exchange.server_ephemeral (a Vec<u8> of length 16) and passes it to compute_shared_secret, which panics on clone_from_slice.

Impact

What kind of vulnerability: CWE-704 (incorrect type conversion / cast — clone_from_slice length mismatch) → deterministic panic → pre-authentication per-connection Denial-of-Service. The attacker does not need the server's private key; any network position that can deliver a malformed KEX_ECDH_REPLY (a rogue server, or a MitM before authentication) suffices.

Who is impacted: any deployment that uses russh::client::connect (or connect_stream) to connect to an attacker-controlled or MitM-reachable SSH server, and that negotiates curve25519-sha256 (the default and most-preferred kex algorithm in russh). A single malformed KEX_ECDH_REPLY kills the client session; the attack is deterministic and single-packet. The panic is isolated to the spawned session task (tokio::spawn catches it and surfaces a JoinError), so the embedding process keeps running — the impact is per-connection DoS, not process crash, unless the embedder installs a custom panic hook that calls std::process::abort.

Workaround: until a fix is released, clients can reduce exposure by disabling curve25519-sha256 in the Preferred::kex list and preferring a kex algorithm whose peer-ephemeral length is validated (e.g. the ECDH-NIST or DH/GEX paths). This is a mitigation, not a fix.

Suggested fix (one-line length check, mirrors the existing server-side server_dh check):

// russh/src/kex/curve25519.rs, at the top of compute_shared_secret:
fn compute_shared_secret(&mut self, remote_pubkey_: &[u8]) -> Result<(), crate::Error> {
    if remote_pubkey_.len() != 32 {
        return Err(crate::Error::Kex);
    }
    let local_secret = self.local_secret.take().ok_or(crate::Error::KexInit)?;
    let mut remote_pubkey = MontgomeryPoint([0; 32]);
    remote_pubkey.0.clone_from_slice(remote_pubkey_);
    let shared = local_secret * remote_pubkey;
    self.shared_secret = Some(shared);
    Ok(())
}

This makes the client-side compute_shared_secret consistent with the existing server-side server_dh check at russh/src/kex/curve25519.rs:61-65 and with the other kex paths that already validate peer ephemeral lengths.

vuln_poc.zip

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🦀crates.iorusshall versions0.62.4cargo update -p russh --precise 0.62.4

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for russh, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update russh to 0.62.4 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-73429 is resolved across your whole dependency graph.

  3. Workarounds

    Cap what an attacker can consume: apply request size, rate and timeout limits in front of the affected component, and run it with memory and CPU limits so exhaustion degrades one worker rather than the whole service.

Frequently Asked Questions

### Summary A malicious SSH server can crash a `russh` client session with a single malformed key-exchange reply, causing a pre-authentication Denial-of-Service before the server host key is verified. The embedding process itself stays up, but the connection is killed deterministically. ### Details Every *other* kex path in `russh` validates the peer ephemeral length before cloning: - `Curve25519Kex::server_dh` (`russh/src/kex/curve25519.rs:61-65`) checks `if pubkey_len != 32 { return Err(crate::Error::Kex); }` before `clone_from_slice`. - The hybrid ML-KEM, ECDH-NIST, and DH/GEX paths a
O3 Security · Impact-Aware SCA

Is CVE-2026-73429 in your dependencies?

Find it across crates.io, including transitive dependencies.

CVE-2026-73429: russh DoS (Medium 5.3) | O3 Security