CVE-2026-102820
Last modified
CVE-2026-102820 is a medium-severity vulnerability rated 6.2/10 on the CVSS scale. pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connect_pageant.
Description
pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connect_pageant. A local process that impersonates the Pageant window can make query_pageant_direct allocate up to approximately 4 GiB and copy beyond the mapped view, reliably crashing a russh client and conditionally exposing adjacent committed memory. This issue is fixed in pageant 0.2.3.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eugeny | russh | < 0.63.2 |
| rust | pageant | < 0.2.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-102820?
How severe is CVE-2026-102820?
How do I fix CVE-2026-102820?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102808PX4 Autopilot through 1.17.0 contains a NULL pointer derefer…6.5
- CVE-2026-102809PX4 Autopilot through 1.17.0 contains an uncontrolled stack …6.5
- CVE-2026-10281A weakness has been identified in Enderfga claw-orchestrator…7.3
- CVE-2026-102810Marmite through 0.4.2 contains a path traversal vulnerabilit…7.5
- CVE-2026-102811Marmite through 0.4.2 contains missing authentication in the…7.5
- CVE-2026-10282A security vulnerability has been detected in Bottelet Dayby…5.3
- CVE-2026-102821Russh is a Rust SSH client and server library. Prior to 0.63…6.5
- CVE-2026-102822Russh is a Rust SSH client and server library. Prior to 0.63…3.7
- CVE-2026-102823Russh is a Rust SSH client and server library. Prior to 0.63…7.5
- CVE-2026-102824Russh is a Rust SSH client and server library. Prior to 0.63…4.3
- CVE-2026-102825Russh is a Rust SSH client and server library. Prior to 0.62…3.7
- CVE-2026-102826simple-git, an interface for running git commands in any nod…8.1
Are you affected by CVE-2026-102820?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
