<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:02:20 +0000</lastBuildDate>
    <item>
      <title>BREW-dvc-CVE-2026-54590 — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a le…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-dvc-cve-2026-54590</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: dvc&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: dvc&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-dvc-cve-2026-54590</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BC02149 — Security fixes in airflow-3 3.1.8-r6</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Package airflow-3 version 3.1.8-r6 fixes 13 vulnerabilities: CVE-2026-53533, CVE-2026-59885, CVE-2026-59886, CVE-2026-59890, CVE-2026-49476...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Package airflow-3 version 3.1.8-r6 fixes 13 vulnerabilities: CVE-2026-53533, CVE-2026-59885, CVE-2026-59886, CVE-2026-59890, CVE-2026-49476...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149</guid>
    </item>
    <item>
      <title>EUVD-2026-335643</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335643</link>
      <description>EUVD-2026-335643</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335643</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54590</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54590</link>
      <description>&lt;p&gt;AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing later expansion in _expand_val and Path(filename).expanduser() to escape the intended authorized-keys directory. This issue is fixed in version 2.23.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing later expansion in _expand_val and Path(filename).expanduser() to escape the intended authorized-keys directory. This issue is fixed in version 2.23.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54590</guid>
    </item>
    <item>
      <title>GHSA-qr67-gv47-xwwh — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a le…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qr67-gv47-xwwh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qr67-gv47-xwwh</guid>
    </item>
    <item>
      <title>PYSEC-2026-3809 — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a le…</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3809</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3809</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54590</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54590</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-asyncssh, Ubuntu:Pro:18.04:LTS: python-asyncssh, Ubuntu:20.04:LTS: python-asyncssh, Ubuntu:Pro:22.04:LTS: python-asyncssh, Ubuntu:Pro:24.04:LTS: python-asyncssh, Ubuntu:25.10: python-asyncssh, Ubuntu:26.04:LTS: python-asyncssh&lt;/p&gt;
&lt;p&gt;AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing later expansion in _expand_val and Path(filename).expanduser() to escape the intended authorized-keys directory. This issue is fixed in version 2.23.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-asyncssh, Ubuntu:Pro:18.04:LTS: python-asyncssh, Ubuntu:20.04:LTS: python-asyncssh, Ubuntu:Pro:22.04:LTS: python-asyncssh, Ubuntu:Pro:24.04:LTS: python-asyncssh, Ubuntu:25.10: python-asyncssh, Ubuntu:26.04:LTS: python-asyncssh&lt;/p&gt;
&lt;p&gt;AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing later expansion in _expand_val and Path(filename).expanduser() to escape the intended authorized-keys directory. This issue is fixed in version 2.23.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54590</guid>
    </item>
  </channel>
</rss>
