Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
864008
AlmaLinux
5669
Alpaquita
13881
Alpine
4544
Android
3402
Azure Linux
15458
BellSoft Hardened Containers
667
Bitnami
9059
Chainguard
10171
CleanStart
1987
CRAN
14
crates.io
2681
Debian
64763
Echo
8426
GHC
3
GIT
101854
GitHub Actions
55
Go
8867
Hackage
32
Hex
310
Julia
1713
Linux
27861
Mageia
6133
Maven
6949
MinimOS
131079
npm
227835
NuGet
1844
opam
26
openEuler
8257
openSUSE
14093
OSS-Fuzz
3984
Packagist
6926
Pub
11
PyPI
24625
Red Hat
22542
Rocky Linux
4048
Root
19118
RubyGems
4707
SUSE
22552
SwiftURL
59
TuxCare
8625
Ubuntu
61934
VSCode
20
Wolfi
7224
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-2wxc-x7rj-hg8f
PyPI/asyncssh
asyncssh has SCP Path Traversal to Arbitrary File Write
5 days ago
Fix available
Severity - 8.1 (High)
GHSA-qr67-gv47-xwwh
PyPI/asyncssh
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
5 days ago
Fix available
Severity - 5.9 (Medium)
PYSEC-2026-2384
PyPI/asyncssh
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
13 Jul
Fix available
Severity - 6.9 (Medium)
GHSA-g794-3fmp-753h
PyPI/asyncssh
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
27 May
Fix available
Severity - 6.9 (Medium)
GHSA-hfmc-7525-mj55
PyPI/asyncssh
AsyncSSH vulnerable to Prefix Truncation Attack (a.k.a. Terrapin Attack) against ChaCha20-Poly1305 and Encrypt-then-MAC
18 Dec 2023
Fix available
Severity - 5.9 (Medium)
PYSEC-2023-237
PyPI/asyncssh
See record for full details
14 Nov 2023
Fix available
Severity - 5.9 (Medium)
PYSEC-2023-239
PyPI/asyncssh
See record for full details
14 Nov 2023
Fix available
Severity - 6.8 (Medium)
GHSA-c35q-ffpf-5qpm
PyPI/asyncssh
AsyncSSH Rogue Session Attack
09 Nov 2023
Fix available
Severity - 8.1 (High)
GHSA-cfc2-wr2v-gxm5
PyPI/asyncssh
AsyncSSH Rogue Extension Negotiation
09 Nov 2023
Fix available
Severity - 5.3 (Medium)
GHSA-97cv-6pjf-5f9q
PyPI/asyncssh
AsyncSSH SSH Server Authentication Bypass
14 May 2022
Fix available
Severity - 9.3 (Critical)
PYSEC-2018-108
PyPI/asyncssh
github.com/ronf/asyncssh
See record for full details
12 Mar 2018
Fix available
PyPI - OSV