PatchSiren cyber security CVE debrief
CVE-2026-46705 Eugeny CVE debrief
A vulnerability was discovered in the Russh Rust SSH client & server library, affecting versions from 0.34.0-beta.1 to before 0.61.0. The issue arises from the Russh server authentication path keeping internal userauth state across SSH_MSG_USERAUTH_REQUEST messages without properly separating that state when the request principal changes. This internal library state mismatch can lead to unintended behavior in later authentication requests for different users or services.
- Vendor
- Eugeny
- Product
- russh
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-10
- Original CVE updated
- 2026-06-11
- Advisory published
- 2026-06-10
- Advisory updated
- 2026-06-11
Who should care
Developers and administrators using the Russh library for SSH functionality in their applications should be aware of this vulnerability. Specifically, those who have not upgraded to version 0.61.0 or later are at risk.
Technical summary
The Russh library fails to reset internal authentication state when the user or service name changes between authentication requests. This can cause issues as the authentication state, such as remaining methods, partial-success state, and in-progress method state, can remain associated with the connection and influence later requests for different users or services.
Defensive priority
MEDIUM
Recommended defensive actions
- Upgrade to Russh version 0.61.0 or later to patch the vulnerability.
- Review and update any applications or services using the affected versions of the Russh library.
Evidence notes
The vulnerability has been patched in version 0.61.0 of the Russh library. For more information, refer to the official CVE record [cve-org] and the NVD detail page [nvd]. Additional details can be found in the security advisory [ref-4].
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46705 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46705
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46705 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46705
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Eugeny/russh/security/advisories/GHSA-hpv4-5h6f-wqr3
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.