Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Modified: 9/10/2026
package
pkg:crates.io/russh
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Modified: 9/10/2026
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
Modified: 6/11/2026
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Modified: 9/10/2026
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
Modified: 6/11/2026
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Modified: 9/10/2026
russh may use insecure Diffie-Hellman keys
Modified: 11/8/2023
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
Modified: 9/10/2026
Russh: Unchecked CryptoVec allocation and growth handling is reachable
Modified: 9/10/2026
Russh: Unchecked keyboard-interactive prompt count in client auth path
Modified: 6/11/2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Modified: 9/10/2026
russh is missing overflow checks during channel windows adjust
Modified: 9/10/2026
russh server userauth state is not reset when authentication principal changes
Modified: 9/10/2026
Russh: Channel-scoped server callbacks can be reached without an open channel
Modified: 9/10/2026
Russh has an OOM Denial of Service due to allocation of untrusted amount
Modified: 8/21/2024
russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
Modified: 9/10/2026
Unbounded 32-bit allocation
Modified: 6/2/2026