<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:24:14.224734+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-06039</id>
    <title>bdu:2022-06039</title>
    <updated>2026-10-02T22:24:14.245861+00:00</updated>
    <content>bdu:2022-06039</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-06039"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2018-7750</id>
    <title>BREW-ansible-CVE-2018-7750 — Paramiko not properly checking authentication before processing other requests</title>
    <updated>2026-10-02T22:24:14.245899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2018-7750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-06104</id>
    <title>cnvd-2018-06104</title>
    <updated>2026-10-02T22:24:14.245935+00:00</updated>
    <content>cnvd-2018-06104</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-06104"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-63388</id>
    <title>EUVD-2026-63388</title>
    <updated>2026-10-02T22:24:14.245950+00:00</updated>
    <content>EUVD-2026-63388</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-63388"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-7750</id>
    <title>fkie_cve-2018-7750</title>
    <updated>2026-10-02T22:24:14.245961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-7750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-232r-66cg-79px</id>
    <title>GHSA-232r-66cg-79px — Paramiko not properly checking authentication before processing other requests</title>
    <updated>2026-10-02T22:24:14.245983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: paramiko</p>
<p>transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-232r-66cg-79px"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-7750</id>
    <title>gsd-2018-7750</title>
    <updated>2026-10-02T22:24:14.246008+00:00</updated>
    <content>gsd-2018-7750</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-7750"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11249-1</id>
    <title>openSUSE-SU-2024:11249-1 — python-paramiko-doc-2.7.2-3.7 on GA media</title>
    <updated>2026-10-02T22:24:14.246020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-paramiko-doc-2.7.2-3.7 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11249-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2018-19</id>
    <title>PYSEC-2018-19</title>
    <updated>2026-10-02T22:24:14.246036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: paramiko</p>
<p>transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2018-19"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:0591</id>
    <title>RHSA-2018:0591 — Red Hat Security Advisory: python-paramiko security and bug fix update</title>
    <updated>2026-10-02T22:24:14.246054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-paramiko: Authentication bypass in transport.py</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:0591"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:0844-1</id>
    <title>SUSE-SU-2018:0844-1 — Security update for python-paramiko</title>
    <updated>2026-10-02T22:24:14.246069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-paramiko</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:0844-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-7750</id>
    <title>UBUNTU-CVE-2018-7750</title>
    <updated>2026-10-02T22:24:14.246082+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: paramiko, Ubuntu:16.04:LTS: paramiko</p>
<p>transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-7750"/>
  </entry>
</feed>
