net-ssh is vulnerable to Denial of Service (DoS)
58
Medium Risk
Net::SSH::Transport::Session#poll_message pushes every packet received during a pending key exchange that is not on the list of packets allowed during KEX onto an unbounded @queue array. A server that completes KEXINIT and then streams non-allowed packets, such as SSH_MSG_USERAUTH_REQUEST, forces the client to buffer all of them before authentication, growing memory without limit until the process is killed or the host runs out of memory. The fix disconnects when a packet arrives out of order during KEX instead of queuing it.
You are affected if you are using a version that falls within the vulnerable range and you connect to an SSH server that is malicious or compromised.
net-ssh is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 7.3.4.
Upgrade the net-ssh library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.