NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #3848 most downloaded on crates.io
A client and server SSH library.
Last release 2 days ago
05 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Rarely documented
notes for 13 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
5 years old
132 releases · first in 2022
One column per quarter.
GHSA-4wc5-f2rc-q74m - Unbounded memory allocation in agent protocol server via crafted constraint records
A local actor or a connected remote server (that the user forwards an agent connection to) can trigger an unlimited memory allocation in a russh-based SSH agent via a crafted message.
5d9d2b8 : drop the legacy ed25519 key parser
legacy-ed25519-pkcs8-parser feature. Legacy keys were written in non-compliant format by russh pre-v0.43. From now on, parsing those keys will return a hard error.Russh server side did not verify that the client signatures were made using the negotiated algorithm. While no bypass is possible through this bug, this allowed a client to e.g. silently downgrade its own signature from rsa-sha2-512 to rsa-sha1
efa9a03: Add support hostkeys-prove-00@openssh.com support (#767) (@inureyes) #767
client::Handle::hostkeys_prove to ask the server to prove ownership of the host keys it announced via hostkeys-00@openssh.com.a0ded76: Support sending custom global requests from the client (#759) (@ChrisJr404) #759
client::Handle::send_global_request(name, data, want_reply)want_reply = false on server-side global requestsFull Changelog: v0.63.3...v0.64.0
c13b259 : enforce inactivity timeout even during stalled writes (Eugene)
GHSA-g4mp-vgx3-xrvm - out-of-bounds read in pageant
pageantA malicious Pageant agent could cause an out-of-bounds read / oversized allocation in the pageant library user.
An authenticated client could trigger unbounded memory allocation during rekey phase
Depending on what the handler does this can lead to a vulnerability.
A mirror of GHSA-m65r-rprj-r5rg for the client side - Handler per-channel callbacks are called even when the server supplies an invalid (never opened) channel ID. Depending on what the handler does this can lead to a vulnerability.
Two peers disagreeing on supported MACs can end up negotiating none MAC for a cipher that requires one, which leads to the session task panicking.
09f6582 : Support host certificates on the client side ( #752 ) ( @biao29 ) #752
09f6582: Support host certificates on the client side (#752) (@biao29) #752
Handler::check_server_key to take a new PublicKeyOrCertificate enum instead of &PublicKeyd7601ae: Support host certificates on the server side (#641) (Georg von Zengen) #641
Config::certificates that functions similarly to Config::keysFull Changelog: v0.62.7...v0.63.0
09f6582 : Support host certificates on the client side ( #752 ) ( @biao29 ) #752
client : support gssapi-with-mic auth ( #738 ) #738 ( ayamir )
GHSA-g6xm-f9xp-qq35 - server-side max_auth_attempts was not enforced - f8fd0b1
max_auth_attempts was not enforced - f8fd0b1Config::max_auth_attempts was not being properly enforced by russh server implementation.
GHSA-m65r-rprj-r5rg - Handler channel callbacks called for non-existing channel - 7c5659f
Handler channel callbacks called for non-existing channel - 7c5659fRussh server did not validate channel IDs passed by a client, so if a client constructed a channel message with an invalid ID, the server-side Handler callback would still get called with that non-existing ID. The consequence of this depend on the specific user implementation.
Full Changelog: v0.62.4...v0.62.5
Three independent bugs have allowed a client to trigger a panic in the session handler task, thereby crashing their own session.
Three independent bugs have allowed a client to trigger a panic in the session handler task, thereby crashing their own session.
2e3f1cc : Update more RustCrypto dependencies to stabilized versions ( #735 ) (kpcyrd) [ #735 ]
6da3f4a : fixed #733 - incorrect first kex guess handling (Eugene)
6fc20b2 : Reply with CHANNEL_CLOSE in server handler per RFC 4254 ( #675 ) (Corey Leavitt) #675
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →