CVE-2026-42189: a pre-auth DoS in russh, found by fuzzing the right state

How designing the fuzz harness around real attacker surface, instead of pointing libfuzzer at every parser I could see, surfaced an unbounded allocation in russh’s keyboard-interactive auth in under 20 minutes.

April 27, 2026 · 10 min · Corey Leavitt