© 2025-2026 PySpect
First version without a known vulnerability: 2.14.2
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
Fixed in: 2.23.0
AsyncSSH vulnerable to Prefix Truncation Attack (a.k.a. Terrapin Attack) against ChaCha20-Poly1305 and Encrypt-then-MAC
Fixed in: 2.14.2
AsyncSSH Rogue Session Attack
Fixed in: 2.14.1
AsyncSSH Rogue Extension Negotiation
Fixed in: 2.14.1
AsyncSSH SSH Server Authentication Bypass
Fixed in: 1.12.1, c161e26cdc0d41b745b63d9f17b437f073bf7ba4