What is CVE-2026-73489?
CVE-2026-73489 is a denial-of-service vulnerability in the Russh Rust SSH library before version 0.62.4. An authenticated SSH client can crash the server by sending a `pty-req` channel request containing more than 130 terminal-mode records, overflowing the fixed-size parser. Upgrading to version 0.62.4 or later is strongly recommended to mitigate the issue.
Azərbaycanca: CVE-2026-73489, Russh Rust SSH kitabxanasında autentifikasiya olunmuş SSH müştərisinin xidmət dayanıqlığını pozmasına imkan verən boşluqdur. 0.62.4 versiyasından əvvəlki versiyalarda, `pty-req` kanal sorğusuna 130-dan çox terminal rejimi qeydi daxil edilməsi parseri aşır. Təsirə məruz qalan sistemlərin ən qısa zamanda 0.62.4 və ya daha yuxarı versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which library is affected by CVE-2026-73489?
This vulnerability affects the Russh Rust SSH library.
What version should be upgraded to in order to mitigate CVE-2026-73489?
Upgrading to version 0.62.4 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.