PatchSiren

Eugeny CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Eugeny CVE published 2026-08-13

CVE-2026-73489

CVE-2026-73489 is a denial-of-service vulnerability in the Russh Rust SSH client and server library. An authenticated SSH client can cause a panic in the server by sending a pty-req channel request with over 130 terminal-mode records. This issue is fixed in version 0.62.4. The vulnerability allows an attacker to terminate the server session task without causing memory corruption. Defenders managing SSH se [truncated]

MEDIUM Eugeny CVE published 2026-08-12

CVE-2026-73430

CVE-2026-73430 is a denial-of-service vulnerability in the Russh Rust SSH client and server library. An unauthenticated SSH client can cause a panic in the server by sending a specially crafted SSH_MSG_KEX_ECDH_INIT message. This issue is fixed in version 0.62.4. The vulnerability allows an attacker to cause a denial-of-service condition, which can impact the availability of affected systems. Defenders sh [truncated]

MEDIUM Eugeny CVE published 2026-08-12

CVE-2026-73429

A vulnerability in the Russh Rust SSH client and server library prior to version 0.62.4 allows a malicious SSH server to crash a client session with a malformed KEX_ECDH_REPLY message. This issue can lead to a denial-of-service (DoS) condition. The vulnerability is caused by a lack of validation in the Curve25519Kex::compute_shared_secret function, which leads to a deterministic panic when a malformed KEX [truncated]

HIGH Eugeny CVE published 2026-08-10

CVE-2026-72903

A highly configurable terminal emulator, Tabby, is vulnerable to a path traversal attack. A malicious SFTP server can return a backslash traversal filename, allowing attacker-controlled content to be created or overwritten outside the selected download directory or temporary edit directory. This vulnerability exists due to the preservation of backslashes as ordinary filename characters in POSIX path proce [truncated]

MEDIUM Eugeny CVE published 2026-08-03

CVE-2026-68930

CVE-2026-68930 is a vulnerability in the Russh Rust SSH client and server library. The issue allows dispatching channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed. This vulnerability was fixed in version 0.62.5. The vulnerability affects Russh library users, and defenders should assess exposure and prioritize upgrading to version 0.62.5 or later. The CVE record [truncated]

HIGH Eugeny CVE published 2026-07-15

CVE-2026-46709

CVE-2026-46709 is a highly severe vulnerability in Tabby terminal emulator versions prior to 1.0.234. The vulnerability allows code execution via dropped file paths due to incomplete neutralization of command substitution metacharacters. This issue was fixed in version 1.0.234. The vulnerability exists in the pathDrop.ts file of Tabby terminal emulator, where dropped file paths are inserted into the activ [truncated]

HIGH Eugeny CVE published 2026-06-10

CVE-2026-48110

CVE-2026-48110 is a vulnerability in the Russh Rust SSH client & server library. The issue affects versions from 0.34.0 up to but not including 0.61.0. In these versions, the library's handling of certain SSH messages could lead to excessive memory allocation or attempts at allocation when processing attacker-controlled strings, name-lists, and byte fields. This could be exploited by a remote SSH peer to [truncated]

MEDIUM Eugeny CVE published 2026-06-10

CVE-2026-48108

The Russh library, a Rust SSH client and server implementation, had a vulnerability from version 0.34.0-beta.1 up to but not including version 0.61.0. This issue relates to how Russh handles the SSH identification string, which is not as strict as OpenSSH. Specifically, the server-side identification reader used a permissive path similar to the client, allowing for pre-banner lines from clients. Moreover, [truncated]

MEDIUM Eugeny CVE published 2026-06-10

CVE-2026-48107

CVE-2026-48107 is a vulnerability in the Russh Rust SSH client & server library. Versions from 0.37.0 up to but not including 0.61.0 are affected. The issue lies in the keyboard-interactive authentication path of the russh client. A malicious SSH server can send a USERAUTH_INFO_REQUEST with an attacker-controlled prompt count. The client then uses this raw count directly in Vec::with_capacity(...) without [truncated]

MEDIUM Eugeny CVE published 2026-06-10

CVE-2026-46705

A vulnerability was discovered in the Russh Rust SSH client & server library, affecting versions from 0.34.0-beta.1 to before 0.61.0. The issue arises from the Russh server authentication path keeping internal userauth state across SSH_MSG_USERAUTH_REQUEST messages without properly separating that state when the request principal changes. This internal library state mismatch can lead to unintended behavio [truncated]

HIGH Eugeny CVE published 2026-06-10

CVE-2026-46702

A remote denial-of-service vulnerability exists in the Russh SSH library, affecting versions 0.34.0 to before 0.61.1. The vulnerability allows a remote peer to send oversized post-decompression packets, causing a resource-exhaustion issue in the post-decompression receive path. This issue has been patched in version 0.61.1.

HIGH Eugeny CVE published 2026-06-10

CVE-2026-46673

Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation/locking paths. In current russh releases, local SSH agent peers could still feed attacker-controlled frame lengths into buffer growth before validation. In older russh releases before 0.58.0, remote SSH traffic also reached CryptoVec through tra [truncated]

HIGH Eugeny CVE published 2026-05-15

CVE-2026-45038

CVE-2026-45038 is a high-severity Tabby vulnerability in drag-and-drop file handling. Before version 1.0.233, Tabby did not escape control characters in file paths when a file was dragged into the terminal emulator, which could result in code execution. The issue is fixed in Tabby 1.0.233. The CVE was published on 2026-05-15 and updated on 2026-05-20.

HIGH Eugeny CVE published 2026-05-15

CVE-2026-45037

CVE-2026-45037 affects Tabby (formerly Terminus) terminal link handling. Before 1.0.232, Tabby passed detected URIs directly to the operating system’s protocol handler without validating the scheme, so a malicious SSH or Telnet server could embed crafted output that appears as a clickable terminal link and causes an unsafe handler to open on the client.

CRITICAL Eugeny CVE published 2026-05-15

CVE-2026-45035

Tabby (formerly Terminus) terminal emulator versions prior to 1.0.233 register a custom URL scheme handler (tabby://) that accepts a run command parameter. When a user clicks a crafted link containing tabby://run?command=..., the operating system launches Tabby, which immediately executes the specified OS command as a child process with the user's full privileges without confirmation, sanitization, or san [truncated]