Asyncssh Project maintains a specialized Python SSH client and server library whose vulnerabilities, while modest in volume, concentrate on authentication and authorization mechanisms—specifically user-controlled key handling, integrity verification, and data authenticity validation—that are critical to SSH protocol security. This niche library's exposure matters disproportionately because SSH implementations are widely embedded in infrastructure automation, DevOps platforms, and remote-access tooling where authentication flaws can undermine the security assumptions of downstream systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asyncssh Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2018-7749CRITICAL The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can si | Mar 12, 2018 | 9.8 | 30 | NO | NO |
CVE-2023-46446MEDIUM An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack | Nov 14, 2023 | 6.8 | 22 | NO | NO |
CVE-2023-46445MEDIUM An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation." | Nov 14, 2023 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asyncssh Project.
Media articles that mention a CVE ID that affects a product developed by Asyncssh Project — matched by CVE ID, not by vendor name.