All 4 CVE vulnerabilities found in asyncssh, with AI-generated Chinese analysis, references, and POCs.
Vendor: ronf
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-62949 | AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION CWE-835 | 6.5 | Medium | 2026-09-16 |
| CVE-2026-45309 | AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username CWE-22 | - | - | 2026-07-17 |
| CVE-2026-54590 | AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion CWE-22 | 5.9 | Medium | 2026-07-08 |
| CVE-2026-54591 | AsyncSSH: SCP Path Traversal to Arbitrary File Write CWE-22 | 8.1 | High | 2026-07-08 |
All 4 known CVE vulnerabilities affecting asyncssh with full Chinese analysis, references, and POCs where available.