A medium-severity vulnerability affecting russh versions <= 0.62.4, tracked as CVE-2026-68930, affects russh versions prior to 0.62.5. The flaw is a server-side channel state issue where the application dispatches channel-scoped handler callbacks for recipient channel IDs that were never opened or confirmed. This can allow an authenticated client to bypass the server application's channel-open policy and potentially execute malicious code. The business impact depends on the downstream application, but in a proof-of-concept, the protected exec_request action ran even though no channel was opened. The vulnerability is not an authentication bypass, as a valid login is required, but rather a failure to enforce the SSH channel lifecycle before delivering channel-scoped callbacks to the application.
We recommend you to update russh to version 0.62.5.[/subscribe_to_unlock_form]
A medium-severity vulnerability affecting russh versions <= 0.62.4, tracked as CVE-2026-68930, affects russh versions prior to 0.62.5. The flaw is a server-side channel state issue where the application dispatches channel-scoped handler callbacks for recipient channel IDs that were never opened or confirmed. This can allow an authenticated client to bypass the server application's channel-open policy and potentially execute malicious code. The business impact depends on the downstream application, but in a proof-of-concept, the protected exec_request action ran even though no channel was opened. The vulnerability is not an authentication bypass, as a valid login is required, but rather a failure to enforce the SSH channel lifecycle before delivering channel-scoped callbacks to the application.
We recommend you to update russh to version 0.62.5.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]