Known vulnerabilities in AsyncSSH

Software: AsyncSSH
Software CPE: cpe:2.3:a:ronf:asyncssh:*:*:*:*:*:*:*:*
Total vulnerabilities: 8
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting AsyncSSH AsyncSSH is affected by 8 known vulnerabilities: 2 high, 5 medium, 1 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU153259 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-77473
CWE-22 Medium
No
No
2.24.1 05.10.2026 SB2026100530
#VU153258 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-62949
CWE-835 Low
No
No
2.24.0 05.10.2026 SB2026100529
#VU153257 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-54591
CWE-22 High
No
No
2.23.1 05.10.2026 SB2026100528
SB2026100534
SB2026100535
and 1 more
#VU153256 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-54590
CWE-22 Medium
No
No
2.23.1 05.10.2026 SB2026100528
SB2026100534
SB2026100535
and 1 more
#VU132349 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-45309
CWE-22 Medium
No
No
2.23.0 27.05.2026 SB2026052718
#VU84955 - Improper Authentication
CVE-2018-7749
CWE-287 High
No
No
1.12.1 03.01.2024 SB2018031235
#VU84954 - Insufficient Verification of Data Authenticity
CVE-2023-46445
CWE-345 Medium
No
No
2.14.1 03.01.2024 SB2024010327
SB2024010328
SB2024020802
and 3 more
#VU84953 - Insufficient Verification of Data Authenticity
CVE-2023-46446
CWE-345 Medium
No
No
2.14.1 03.01.2024 SB2024010327
SB2024010328
SB2024020802
and 8 more