14 Total advisories
14 Vulnerabilities
0 Malware
Dependency scanning
Check whether asyncssh is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.5
CVE-2026-62949
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
HIGH 8.1
CVE-2026-54591
asyncssh has SCP Path Traversal to Arbitrary File Write
MEDIUM 5.9
CVE-2026-54590
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
HIGH 8.1
CVE-2026-54591
asyncssh has SCP Path Traversal to Arbitrary File Write
MEDIUM 5.9
CVE-2026-54590
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
UNKNOWN
CVE-2026-45309
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
UNKNOWN
CVE-2026-45309
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
MEDIUM 5.3
CVE-2023-46445
AsyncSSH Rogue Extension Negotiation
HIGH 8.1
CVE-2023-46446
AsyncSSH Rogue Session Attack
UNKNOWN
CVE-2018-7749
CVE-2018-7749
CRITICAL 9.8
CVE-2018-7749
AsyncSSH SSH Server Authentication Bypass
MEDIUM 5.9
GHSA-hfmc-7525-mj55
AsyncSSH vulnerable to Prefix Truncation Attack (a.k.a. Terrapin Attack) against ChaCha20-Poly1305 and Encrypt-then-MAC
MEDIUM 6.8
CVE-2023-46446
CVE-2023-46446
MEDIUM 5.9
CVE-2023-46445
CVE-2023-46445
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes