Security research and tooling. Disclosed CVE-2026-42189.
CVE-2026-42189: a pre-auth DoS in russh, found by fuzzing the right state
How designing the fuzz harness around real attacker surface, instead of pointing libfuzzer at every parser I could see, surfaced an unbounded allocation in russh’s keyboard-interactive auth in under 20 minutes.