© 2025-2026 PySpect
First version without a known vulnerability: 2.24.0
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
Fixed in: 2.24.0
asyncssh has SCP Path Traversal to Arbitrary File Write
Fixed in: 2.23.1
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
Fixed in: 2.23.1
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
Fixed in: 2.23.0
AsyncSSH vulnerable to Prefix Truncation Attack (a.k.a. Terrapin Attack) against ChaCha20-Poly1305 and Encrypt-then-MAC
Fixed in: 2.14.2
AsyncSSH Rogue Session Attack
Fixed in: 2.14.1
AsyncSSH Rogue Extension Negotiation
Fixed in: 2.14.1
AsyncSSH SSH Server Authentication Bypass
Fixed in: 1.12.1, c161e26cdc0d41b745b63d9f17b437f073bf7ba4