Intel

AIKIDO-2026-563009

net-ssh is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-rpq3-v334-f5pm Published Yesterday

53

Medium Risk

This Affects:

RUBYnet-ssh
0.0.1 - 7.3.4
Fixed in 7.3.5
Are you affected? Scan for Free

TL;DR

Net::SSH::KeyFactory.load_data_private_key parses OpenSSH private keys through bcrypt_pbkdf without bounding the number of key derivation rounds encoded in the key file. A crafted key with an extreme round count locks the process in CPU bound derivation for an effectively unbounded time, even though the file is not a valid SSH key.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you load a private key file from an untrusted source.

Background info

net-ssh is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 7.3.4.

How to fix this

Upgrade the net-ssh library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform