CVE-2026-45309
Description
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, AsyncSSH expands the OpenSSH-compatible AuthorizedKeysFile %u token in asyncssh/config.py, asyncssh/connection.py, asyncssh/auth_keys.py, and asyncssh/misc.py with the raw SSH username during pre-authentication server config reload, allowing a server configured with AuthorizedKeysFile authorized_keys/%u to read an authorized-keys file outside the intended directory when the SSH username contains /, \, or .. path traversal segments and authenticate with an attacker-selected key file. This issue is fixed in version 2.23.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
asyncsshPyPI | >= 2.22.0, < 2.23.0 | 2.23.0 |
Affected products
5- osv-coords3 versionspkg:apk/chainguard/airflow-3pkg:apk/wolfi/airflow-3pkg:rpm/opensuse/python-asyncssh&distro=openSUSE%20Tumbleweed
< 3.2.1-r4+ 2 more
- (no CPE)range: < 3.2.1-r4
- (no CPE)range: < 3.2.1-r4
- (no CPE)range: < 2.23.1-1.1
Patches
Vulnerability mechanics
References
4- github.com/ronf/asyncssh/commit/2af2382cce946c959a378a62f257af253dc4ab51nvdPatch
- github.com/ronf/asyncssh/commit/3d515ba9ba0cd9990d248bdf62bcf05d51261a88nvdPatch
- github.com/ronf/asyncssh/security/advisories/GHSA-g794-3fmp-753hnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-g794-3fmp-753hghsaADVISORY
News mentions
0No linked articles in our index yet.