GHSA-g9hv-x236-4qp3: Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
A malicious SSH server can crash a russh client session with a single
malformed key-exchange reply, causing a pre-authentication Denial-of-Service
before the server host key is verified. The embedding process itself stays
up, but the connection is killed deterministically.
References
Code Behaviors & Features
Detect and mitigate GHSA-g9hv-x236-4qp3 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →