<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 16:29:11 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-11318</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-11318</link>
      <description>bdu:2024-11318</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-11318</guid>
    </item>
    <item>
      <title>BREW-dvc-CVE-2023-46445 — AsyncSSH Rogue Extension Negotiation</title>
      <link>https://cve.radiocsirt.org/vuln/brew-dvc-cve-2023-46445</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: dvc&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The rogue extension negotiation attack targets an AsyncSSH client connecting to any SSH server sending an extension info message. The attack exploits an implementation flaw in the AsyncSSH implementation to inject an extension info message chosen by the attacker and delete the original extension info message, effectively replacing it.&lt;/p&gt;
&lt;p&gt;A correct SSH implementation should not process an unauthenticated extension info message. However, the injected message is accepted due to flaws in AsyncSSH. AsyncSSH supports the server-sig-algs and global-requests-ok extensions. Hence, the attacker can downgrade the algorithm used for client authentication by meddling with the value of server-sig-algs (e.g. use of SHA-1 instead of SHA-2).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
    &amp;lt;summary&amp;gt;AsyncSSH Client 2.14.0 (simple_client.py example) connecting to AsyncSSH Server 2.14.0 (simple_server.py example)&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;```python
    #!/usr/bin/python3
    import socket
    from threading import Thread
    from binascii import unhexlify
    
    #####################################################################################
    ## Proof of Concept for the rogue extension negotiation attack (ChaCha20-Poly1305) ##
    ##                                                                                 ##
    ## Client(s) tested: AsyncSSH 2.14.0 (sim…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: dvc&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The rogue extension negotiation attack targets an AsyncSSH client connecting to any SSH server sending an extension info message. The attack exploits an implementation flaw in the AsyncSSH implementation to inject an extension info message chosen by the attacker and delete the original extension info message, effectively replacing it.&lt;/p&gt;
&lt;p&gt;A correct SSH implementation should not process an unauthenticated extension info message. However, the injected message is accepted due to flaws in AsyncSSH. AsyncSSH supports the server-sig-algs and global-requests-ok extensions. Hence, the attacker can downgrade the algorithm used for client authentication by meddling with the value of server-sig-algs (e.g. use of SHA-1 instead of SHA-2).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
    &amp;lt;summary&amp;gt;AsyncSSH Client 2.14.0 (simple_client.py example) connecting to AsyncSSH Server 2.14.0 (simple_server.py example)&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;```python
    #!/usr/bin/python3
    import socket
    from threading import Thread
    from binascii import unhexlify
    
    #####################################################################################
    ## Proof of Concept for the rogue extension negotiation attack (ChaCha20-Poly1305) ##
    ##                                                                                 ##
    ## Client(s) tested: AsyncSSH 2.14.0 (sim…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-dvc-cve-2023-46445</guid>
    </item>
    <item>
      <title>EUVD-2026-270669</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270669</link>
      <description>EUVD-2026-270669</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270669</guid>
    </item>
    <item>
      <title>fkie_cve-2023-46445</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46445</link>
      <description>&lt;p&gt;An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a &amp;#34;Rogue Extension Negotiation.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a &amp;#34;Rogue Extension Negotiation.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-46445</guid>
    </item>
    <item>
      <title>GHSA-cfc2-wr2v-gxm5 — AsyncSSH Rogue Extension Negotiation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cfc2-wr2v-gxm5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The rogue extension negotiation attack targets an AsyncSSH client connecting to any SSH server sending an extension info message. The attack exploits an implementation flaw in the AsyncSSH implementation to inject an extension info message chosen by the attacker and delete the original extension info message, effectively replacing it.&lt;/p&gt;
&lt;p&gt;A correct SSH implementation should not process an unauthenticated extension info message. However, the injected message is accepted due to flaws in AsyncSSH. AsyncSSH supports the server-sig-algs and global-requests-ok extensions. Hence, the attacker can downgrade the algorithm used for client authentication by meddling with the value of server-sig-algs (e.g. use of SHA-1 instead of SHA-2).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
    &amp;lt;summary&amp;gt;AsyncSSH Client 2.14.0 (simple_client.py example) connecting to AsyncSSH Server 2.14.0 (simple_server.py example)&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;```python
    #!/usr/bin/python3
    import socket
    from threading import Thread
    from binascii import unhexlify
    
    #####################################################################################
    ## Proof of Concept for the rogue extension negotiation attack (ChaCha20-Poly1305) ##
    ##                                                                                 ##
    ## Client(s) tested: AsyncSSH 2.14.0 (sim…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The rogue extension negotiation attack targets an AsyncSSH client connecting to any SSH server sending an extension info message. The attack exploits an implementation flaw in the AsyncSSH implementation to inject an extension info message chosen by the attacker and delete the original extension info message, effectively replacing it.&lt;/p&gt;
&lt;p&gt;A correct SSH implementation should not process an unauthenticated extension info message. However, the injected message is accepted due to flaws in AsyncSSH. AsyncSSH supports the server-sig-algs and global-requests-ok extensions. Hence, the attacker can downgrade the algorithm used for client authentication by meddling with the value of server-sig-algs (e.g. use of SHA-1 instead of SHA-2).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
    &amp;lt;summary&amp;gt;AsyncSSH Client 2.14.0 (simple_client.py example) connecting to AsyncSSH Server 2.14.0 (simple_server.py example)&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;```python
    #!/usr/bin/python3
    import socket
    from threading import Thread
    from binascii import unhexlify
    
    #####################################################################################
    ## Proof of Concept for the rogue extension negotiation attack (ChaCha20-Poly1305) ##
    ##                                                                                 ##
    ## Client(s) tested: AsyncSSH 2.14.0 (sim…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cfc2-wr2v-gxm5</guid>
    </item>
    <item>
      <title>gsd-2023-46445</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-46445</link>
      <description>gsd-2023-46445</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-46445</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13417-1 — python310-asyncssh-2.14.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13417-1</link>
      <description>&lt;p&gt;python310-asyncssh-2.14.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-asyncssh-2.14.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13417-1</guid>
    </item>
    <item>
      <title>PYSEC-2023-237</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2023-237</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2023-237</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-46445</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46445</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-asyncssh, Ubuntu:Pro:18.04:LTS: python-asyncssh, Ubuntu:20.04:LTS: python-asyncssh, Ubuntu:22.04:LTS: python-asyncssh, Ubuntu:Pro:24.04:LTS: python-asyncssh&lt;/p&gt;
&lt;p&gt;An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a &amp;#34;Rogue Extension Negotiation.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-asyncssh, Ubuntu:Pro:18.04:LTS: python-asyncssh, Ubuntu:20.04:LTS: python-asyncssh, Ubuntu:22.04:LTS: python-asyncssh, Ubuntu:Pro:24.04:LTS: python-asyncssh&lt;/p&gt;
&lt;p&gt;An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a &amp;#34;Rogue Extension Negotiation.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46445</guid>
    </item>
  </channel>
</rss>
