VulnSea

asyncssh vulnerabilities

CVEs whose affected-version data names the asyncssh package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-62949Medium· 6.5
6d ago

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in a…

Sunlitronf · asyncsshEPSS 0.39%via NVD
CVE-2026-54590Medium· 5.9
3w ago

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakl…

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

Sunlitasyncssh · asyncsshEPSS 0.39%via OSV
CVE-2026-54591High· 8.1
3w ago

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh has SCP Path Traversal to Arbitrary File Write

Twilightasyncssh · asyncsshEPSS 0.49%via OSV
CVE-2026-45309Medium
3mo ago

AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username

AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username

Sunlitasyncssh · asyncsshEPSS 0.44%via OSV
CVE-2023-46445Medium· 5.3
2y ago

AsyncSSH Rogue Extension Negotiation

AsyncSSH Rogue Extension Negotiation

Sunlitasyncssh · asyncsshEPSS 0.59%via OSV
CVE-2023-46446High· 8.1
2y ago

AsyncSSH Rogue Session Attack

AsyncSSH Rogue Session Attack

Twilightasyncssh · asyncsshEPSS 0.87%via OSV
asyncssh vulnerabilities (CVEs) · VulnSea