GHSA-f5v4-2wr6-hqmg: russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
A pre-authentication denial-of-service vulnerability exists in the server’s keyboard-interactive authentication handler. A malicious client can crash any russh-based server that implements keyboard-interactive auth (e.g., for 2FA/TOTP) with a single malformed packet, requiring no credentials.
References
Code Behaviors & Features
Detect and mitigate GHSA-f5v4-2wr6-hqmg with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →