asyncssh has 5 CVEs on record between 2023 and 2026. 2 were published in the last 90 days. The median CVSS is 7.0 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.0
- Publish → KEV
- —
- Last 90 days
- 2 prev 1
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-54591High· 8.1asyncssh has SCP Path Traversal to Arbitrary File Write45CVE-2023-46446High· 8.1AsyncSSH Rogue Session Attack45CVE-2026-54590Medium· 5.9asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakl…33CVE-2023-46445Medium· 5.3AsyncSSH Rogue Extension Negotiation29CVE-2026-45309MediumAsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username28
asyncssh vulnerabilities
CVEs affecting asyncssh, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-54590Medium· 5.9asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakl…
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
▾ Sunlitasyncssh · asyncsshEPSS 0.39%via OSV
CVE-2026-54591High· 8.1asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh has SCP Path Traversal to Arbitrary File Write
▾ Twilightasyncssh · asyncsshEPSS 0.49%via OSV
CVE-2026-45309MediumAsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
▾ Sunlitasyncssh · asyncsshEPSS 0.44%via OSV
CVE-2023-46445Medium· 5.3AsyncSSH Rogue Extension Negotiation
AsyncSSH Rogue Extension Negotiation
▾ Sunlitasyncssh · asyncsshEPSS 0.59%via OSV
CVE-2023-46446High· 8.1AsyncSSH Rogue Session Attack
AsyncSSH Rogue Session Attack
▾ Twilightasyncssh · asyncsshEPSS 0.87%via OSV