paramiko
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting paramikopage 1 of 1
- CVE-2008-0299NONECVSS 0.0EG 0.0✓ Fixed in 1.7.22008-01-16
vulnerable: 0.1-bulbasaur ... 1.7.1 (24 versions)
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
- CVE-2018-1000805HIGHCVSS 8.8EG 8.8✓ Fixed in 2.0.92018-10-08
vulnerable: 1.10.0 ... 2.0.8 (80 versions)
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
- CVE-2018-7750CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.18.52018-03-13
vulnerable: 0.1-bulbasaur ... 2.3.1 (101 versions)
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentic…
- CVE-2022-24302MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2.10.12022-03-17
vulnerable: 0.1-bulbasaur ... 2.9.2 (127 versions)
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
- CVE-2023-48795MEDIUMCVSS 5.9EG 5.9✓ Fixed in 3.4.02023-12-18
vulnerable: 2.10.0 ... 3.3.2 (30 versions)
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and…
- CVE-2026-44405LOWCVSS 3.4EG 3.42026-05-06
vulnerable: 0.1-bulbasaur ... 4.0.0 (150 versions)
In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
Check whether paramiko is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for paramiko CVEs against the assets you own.
Start Free Scan →