common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
Loading...
Loading...
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
January 16, 2008
April 23, 2026
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| paramiko | 0.1-bulbasaur ... 1.7.1 (24 versions) | 1.7.2 | — |
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-0299
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.