Paramiko is a widely embedded Python SSH library that provides secure shell protocol functionality across numerous server automation, infrastructure management, and DevOps tools, despite a narrow direct product surface. The vulnerability surface centers on authentication and synchronization issues—including race conditions, improper authentication handling, improper integrity validation, and authorization flaws—that reflect the complexity of state management and cryptographic protocol implementation in SSH clients. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paramiko over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2018-7750CRITICAL transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2 | Mar 13, 2018 | 9.8 | 56 | NO | YES |
CVE-2018-1000805HIGH Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be | Oct 8, 2018 | 8.8 | 30 | NO | NO |
CVE-2022-24302MEDIUM In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure. | Mar 17, 2022 | 5.9 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paramiko.
Media articles that mention a CVE ID that affects a product developed by Paramiko — matched by CVE ID, not by vendor name.