asyncssh
PyPI7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting asyncsshpage 1 of 1
- CVE-2018-7749CRITICALCVSS 9.8EG 9.8fixed in 1.12.12018-03-12
vulnerable: 0.8.1 ... v0.1.0 (86 versions)
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.
- CVE-2023-46445MEDIUMCVSS 5.9EG 5.9fixed in 2.14.12023-11-14
vulnerable: 0.8.1 ... 2.9.0 (78 versions)
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
- CVE-2023-46446MEDIUMCVSS 6.8EG 6.8fixed in 2.14.12023-11-14
vulnerable: 0.8.1 ... 2.9.0 (78 versions)
An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
- CVE-2026-45309HIGHCVSS 7.5EG 7.5fixed in 2.23.02026-05-27
vulnerable: 2.22.0
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, AsyncSSH expands the OpenSSH-compatible AuthorizedKeysFile %u token…
- CVE-2026-54590MEDIUMCVSS 5.9EG 5.9fixed in 2.23.12026-07-08
vulnerable: 0.8.1 ... 2.9.0 (90 versions)
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set…
- CVE-2026-54591HIGHCVSS 8.1EG 8.1fixed in 2.23.12026-07-08
vulnerable: 0.8.1 ... 2.9.0 (90 versions)
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SC…
- CVE-2026-62949MEDIUMCVSS 6.5EG 6.5fixed in 2.24.02026-09-16
vulnerable: 0.8.1 ... 2.9.0 (91 versions)
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in asy…
Check whether asyncssh is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for asyncssh CVEs against the assets you own.
Book a Demo →