Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-102825 is a vulnerability in the Eugeny russh Rust SSH client and server library that allows an unauthenticated remote client to bypass the configured maximum authentication attempts limit. Prior to version 0.62.6, the authentication attempt counter increments but is never compared against the maximum allowed attempts, enabling excessive authentication requests on a single connection. This increases the risk of online guessing attacks and adds unnecessary backend authentication workload. The issue is fixed in version 0.62.6. Join the discussion | CVE Database V5 | 09/29/2026, 18:31:32 UTC Added: 09/29/2026, 18:51:53 UTC |
0 CVE-2026-102824 is a vulnerability in the Eugeny russh Rust SSH client and server library prior to version 0.63.0. The issue involves the hybrid ML-KEM 768 and X25519 key exchange implementation accepting an all-zero 32-byte peer X25519 public key, which causes the X25519 contribution to the combined shared secret to be zero. This allows a malicious SSH peer to force the shared secret to depend solely on ML-KEM, undermining the hybrid exchange's fallback protection. The vulnerability is fixed in version 0.63.0. Join the discussion | CVE Database V5 | 09/29/2026, 18:27:41 UTC Added: 09/29/2026, 18:37:06 UTC |
CVE-2026-102823 is an improper input validation vulnerability in the Eugeny russh Rust SSH client and server library. Versions prior to 0.63.1 improperly forward certain SSH channel lifecycle events to client handlers without verifying that the channel identifiers belong to channels the client opened and established. This can allow a malicious SSH server to send events for channels that are unopened or released, potentially causing application panics or corrupting command completion and exit-code tracking. The issue is fixed in version 0.63.1. Join the discussion | CVE Database V5 | 09/29/2026, 18:25:58 UTC Added: 09/29/2026, 18:37:06 UTC |
Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needs_mac() only when MAC selection fails. A remote peer can then send a packet with a decrypted length of zero, causing russh/src/cipher/mod.rs to shrink the previously read block before indexing buffer.buffer[16..], which panics and terminates the connection task. This issue is fixed in version 0.63.1. Join the discussion | CVE Database V5 | 09/29/2026, 18:23:28 UTC Added: 09/29/2026, 18:37:06 UTC |
CVE-2026-102821 is a vulnerability in the Eugeny russh Rust SSH client and server library prior to version 0.63.2. An authenticated remote peer can exploit the server by sending SSH_MSG_KEXINIT messages without the required SSH_MSG_KEX_ECDH_INIT, then flooding SSH_MSG_CHANNEL_OPEN messages. This causes the server to enqueue replies on an unbounded channel without draining, leading to uncontrolled memory growth and potential process termination. The issue is fixed in version 0.63.2. Join the discussion | CVE Database V5 | 09/29/2026, 18:21:21 UTC Added: 09/29/2026, 18:37:06 UTC |
0 CVE-2026-102820 is an out-of-bounds read vulnerability in the Eugeny russh project, specifically in the Windows pageant crate prior to version 0.2.3. The vulnerability arises from the MemoryMap::read function trusting a peer-controlled 32-bit response length, which can lead to reading beyond the allocated shared memory. This can cause a local process impersonating the Pageant window to crash the russh client and potentially expose adjacent committed memory. The issue is fixed in pageant version 0.2.3. Join the discussion | CVE Database V5 | 09/29/2026, 18:18:43 UTC Added: 09/29/2026, 18:37:06 UTC |
Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a pty-req channel request with more than 130 terminal-mode records. The parser in russh/src/server/encrypted.rs stores terminal modes in a fixed 130-entry [(Pty::TTY_OP_END, 0); 130] array but continues increasing the mode count, then constructs an out-of-bounds slice and panics before the application pty_request handler runs. The panic terminates the server session task without causing memory corruption. This issue is fixed in version 0.62.4. Join the discussion | CVE Database V5 | 08/13/2026, 22:04:44 UTC Added: 08/13/2026, 22:12:00 UTC |
0 Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte all-zero Q_C value. Curve25519Kex::server_dh in russh/src/kex/curve25519.rs accepts the all-zero peer public value and computes an all-zero shared secret, after which compute_exchange_hash calls encode_mpint in russh/src/kex/mod.rs and indexes beyond the end of the input while skipping leading zero bytes. The resulting panic occurs before authentication and terminates the server key-exchange task. This issue is fixed in version 0.62.4. Join the discussion | CVE Database V5 | 08/12/2026, 20:55:38 UTC Added: 08/12/2026, 21:13:14 UTC |
Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ephemeral value that is not 32 bytes long. The client-side Curve25519Kex::compute_shared_secret function in russh/src/kex/curve25519.rs passes the decoded exchange.server_ephemeral value to clone_from_slice without validating its length, causing a deterministic panic before the server host key is verified. The panic terminates the spawned client session task and surfaces as a JoinError, while the embedding process normally remains running. This issue is fixed in version 0.62.4. Join the discussion | CVE Database V5 | 08/12/2026, 20:53:19 UTC Added: 08/12/2026, 21:13:14 UTC |
0 Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue. Join the discussion | CVE Database V5 | 08/03/2026, 15:34:41 UTC Added: 08/03/2026, 16:18:42 UTC |
Showing 1 to 10 of 17 results