{"api_version":"v1","generated_at":"2026-10-07T20:20:00+00:00","product":{"cve_count":19,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-eugeny-russh-a7e2f5980447","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/russh","name":"russh","next_cursor":null,"observations":[{"affected":"russh: < 0.62.6","affected_versions_present":true,"cve_id":"CVE-2026-102825","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-102825","fixed":"0.62.6.","last_modified":"2026-09-30T19:29:26.432Z","patch_url":"https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35","primary_source":"","published":"2026-09-29T18:31:32.393Z"},{"affected":"russh: < 0.63.0","affected_versions_present":true,"cve_id":"CVE-2026-102824","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-102824","fixed":"0.63.0.","last_modified":"2026-09-30T20:24:58.381Z","patch_url":"https://github.com/Eugeny/russh/security/advisories/GHSA-w3jg-pjxf-73p4","primary_source":"","published":"2026-09-29T18:27:41.650Z"},{"affected":"russh: < 0.63.1","affected_versions_present":true,"cve_id":"CVE-2026-102823","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-102823","fixed":"0.63.1.","last_modified":"2026-10-02T12:20:10.605Z","patch_url":"https://github.com/Eugeny/russh/security/advisories/GHSA-47hw-gvq5-r2gm","primary_source":"","published":"2026-09-29T18:25:58.084Z"},{"affected":"russh: < 0.63.1","affected_versions_present":true,"cve_id":"CVE-2026-102822","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-102822","fixed":"0.63.1.","last_modified":"2026-09-29T19:53:30.291Z","patch_url":"https://github.com/Eugeny/russh/security/advisories/GHSA-p8qx-h547-fjw9","primary_source":"","published":"2026-09-29T18:23:28.061Z"},{"affected":"russh: < 0.63.2","affected_versions_present":true,"cve_id":"CVE-2026-102821","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-102821","fixed":"0.63.2.","last_modified":"2026-09-30T19:35:02.962Z","patch_url":"https://github.com/Eugeny/russh/security/advisories/GHSA-35g8-35p8-c8fw","primary_source":"","published":"2026-09-29T18:21:21.858Z"},{"affected":"russh: < 0.63.2; pageant: < 0.2.3","affected_versions_present":true,"cve_id":"CVE-2026-102820","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-102820","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-30T20:11:08.453Z","patch_url":"","primary_source":"","published":"2026-09-29T18:18:43.297Z"},{"affected":"russh: < 0.62.4","affected_versions_present":true,"cve_id":"CVE-2026-73489","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73489","fixed":"0.62.4.","last_modified":"2026-08-17T19:50:33.126Z","patch_url":"https://github.com/Eugeny/russh/security/advisories/GHSA-cqjc-rmpq-xprq","primary_source":"","published":"2026-08-13T22:04:44.470Z"},{"affected":"< 0.62.4","affected_versions_present":true,"cve_id":"CVE-2026-73430","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73430","fixed":"0.62.4.","last_modified":"2026-08-13T17:53:22.532Z","patch_url":"https://github.com/Eugeny/russh/security/advisories/GHSA-5xvq-cp9x-6p6r","primary_source":"","published":"2026-08-12T20:55:38.202Z"},{"affected":"< 0.62.4","affected_versions_present":true,"cve_id":"CVE-2026-73429","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73429","fixed":"0.62.4.","last_modified":"2026-08-14T22:15:45.159Z","patch_url":"https://github.com/Eugeny/russh/security/advisories/GHSA-g9hv-x236-4qp3","primary_source":"","published":"2026-08-12T20:53:19.558Z"},{"affected":"< 0.62.5","affected_versions_present":true,"cve_id":"CVE-2026-68930","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-68930","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-03T16:46:32.324Z","patch_url":"","primary_source":"","published":"2026-08-03T15:34:41.216Z"},{"affected":">= 0.34.0, < 0.61.0","affected_versions_present":true,"cve_id":"CVE-2026-48110","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48110","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T16:15:23.673Z","patch_url":"","primary_source":"","published":"2026-06-10T20:26:29.994Z"},{"affected":">= 0.34.0-beta.1, < 0.61.0","affected_versions_present":true,"cve_id":"CVE-2026-48108","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48108","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T13:50:36.699Z","patch_url":"","primary_source":"","published":"2026-06-10T20:24:56.666Z"},{"affected":">= 0.37.0, < 0.61.0","affected_versions_present":true,"cve_id":"CVE-2026-48107","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48107","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T13:05:20.827Z","patch_url":"","primary_source":"","published":"2026-06-10T20:23:45.325Z"},{"affected":">= 0.34.0-beta.1, < 0.61.0","affected_versions_present":true,"cve_id":"CVE-2026-46705","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46705","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T14:14:16.876Z","patch_url":"","primary_source":"","published":"2026-06-10T20:21:35.177Z"},{"affected":">= 0.34.0, < 0.61.1","affected_versions_present":true,"cve_id":"CVE-2026-46702","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46702","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T16:15:30.354Z","patch_url":"","primary_source":"","published":"2026-06-10T20:19:18.792Z"},{"affected":"< 0.60.3","affected_versions_present":true,"cve_id":"CVE-2026-46673","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46673","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T14:33:14.237Z","patch_url":"","primary_source":"","published":"2026-06-10T20:16:28.001Z"},{"affected":"< 0.60.1","affected_versions_present":true,"cve_id":"CVE-2026-42189","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42189","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-11T14:23:49.308Z","patch_url":"https://github.com/Eugeny/russh/commit/6c3c80a9b6d60763d6227d60fa8310e57172a4d1","primary_source":"","published":"2026-05-08T19:49:51.179Z"},{"affected":"< 0.54.1","affected_versions_present":true,"cve_id":"CVE-2025-54804","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54804","fixed":"0.54.1.","last_modified":"2025-08-05T14:44:05.415Z","patch_url":"https://github.com/Eugeny/russh/commit/0eb5e406780890e21ff71dd25d731b30676478e5","primary_source":"","published":"2025-08-05T00:05:20.971Z"},{"affected":"< 0.44.1","affected_versions_present":true,"cve_id":"CVE-2024-43410","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-43410","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-21T15:35:25.998Z","patch_url":"https://github.com/Eugeny/russh/commit/f660ea3f64b86d11d19e33076012069f02431e55","primary_source":"","published":"2024-08-21T15:09:34.316Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Eugeny"}}
