<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T16:29:18.667874+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-11318</id>
    <title>bdu:2024-11318</title>
    <updated>2026-10-05T16:29:18.674788+00:00</updated>
    <content>bdu:2024-11318</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-11318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-dvc-cve-2023-46445</id>
    <title>BREW-dvc-CVE-2023-46445 — AsyncSSH Rogue Extension Negotiation</title>
    <updated>2026-10-05T16:29:18.674829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: dvc</p>
<p>### Summary</p>
<p>An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.</p>
<p>### Details</p>
<p>The rogue extension negotiation attack targets an AsyncSSH client connecting to any SSH server sending an extension info message. The attack exploits an implementation flaw in the AsyncSSH implementation to inject an extension info message chosen by the attacker and delete the original extension info message, effectively replacing it.</p>
<p>A correct SSH implementation should not process an unauthenticated extension info message. However, the injected message is accepted due to flaws in AsyncSSH. AsyncSSH supports the server-sig-algs and global-requests-ok extensions. Hence, the attacker can downgrade the algorithm used for client authentication by meddling with the value of server-sig-algs (e.g. use of SHA-1 instead of SHA-2).</p>
<p>### PoC</p>
<p>&lt;details&gt;
    &lt;summary&gt;AsyncSSH Client 2.14.0 (simple_client.py example) connecting to AsyncSSH Server 2.14.0 (simple_server.py example)&lt;/summary&gt;</p>
<p>```python
    #!/usr/bin/python3
    import socket
    from threading import Thread
    from binascii import unhexlify
    
    #####################################################################################
    ## Proof of Concept for the rogue extension negotiation attack (ChaCha20-Poly1305) ##
    ##                                                                                 ##
    ## Client(s) tested: AsyncSSH 2.14.0 (sim…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-dvc-cve-2023-46445"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-270669</id>
    <title>EUVD-2026-270669</title>
    <updated>2026-10-05T16:29:18.674902+00:00</updated>
    <content>EUVD-2026-270669</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-270669"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46445</id>
    <title>fkie_cve-2023-46445</title>
    <updated>2026-10-05T16:29:18.674917+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-46445"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cfc2-wr2v-gxm5</id>
    <title>GHSA-cfc2-wr2v-gxm5 — AsyncSSH Rogue Extension Negotiation</title>
    <updated>2026-10-05T16:29:18.674942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: asyncssh</p>
<p>### Summary</p>
<p>An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.</p>
<p>### Details</p>
<p>The rogue extension negotiation attack targets an AsyncSSH client connecting to any SSH server sending an extension info message. The attack exploits an implementation flaw in the AsyncSSH implementation to inject an extension info message chosen by the attacker and delete the original extension info message, effectively replacing it.</p>
<p>A correct SSH implementation should not process an unauthenticated extension info message. However, the injected message is accepted due to flaws in AsyncSSH. AsyncSSH supports the server-sig-algs and global-requests-ok extensions. Hence, the attacker can downgrade the algorithm used for client authentication by meddling with the value of server-sig-algs (e.g. use of SHA-1 instead of SHA-2).</p>
<p>### PoC</p>
<p>&lt;details&gt;
    &lt;summary&gt;AsyncSSH Client 2.14.0 (simple_client.py example) connecting to AsyncSSH Server 2.14.0 (simple_server.py example)&lt;/summary&gt;</p>
<p>```python
    #!/usr/bin/python3
    import socket
    from threading import Thread
    from binascii import unhexlify
    
    #####################################################################################
    ## Proof of Concept for the rogue extension negotiation attack (ChaCha20-Poly1305) ##
    ##                                                                                 ##
    ## Client(s) tested: AsyncSSH 2.14.0 (sim…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cfc2-wr2v-gxm5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-46445</id>
    <title>gsd-2023-46445</title>
    <updated>2026-10-05T16:29:18.674994+00:00</updated>
    <content>gsd-2023-46445</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-46445"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13417-1</id>
    <title>openSUSE-SU-2024:13417-1 — python310-asyncssh-2.14.1-1.1 on GA media</title>
    <updated>2026-10-05T16:29:18.675006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-asyncssh-2.14.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13417-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-237</id>
    <title>PYSEC-2023-237</title>
    <updated>2026-10-05T16:29:18.675023+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: asyncssh</p>
<p>An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46445</id>
    <title>UBUNTU-CVE-2023-46445</title>
    <updated>2026-10-05T16:29:18.675039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: python-asyncssh, Ubuntu:Pro:18.04:LTS: python-asyncssh, Ubuntu:20.04:LTS: python-asyncssh, Ubuntu:22.04:LTS: python-asyncssh, Ubuntu:Pro:24.04:LTS: python-asyncssh</p>
<p>An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46445"/>
  </entry>
</feed>
