<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:56:40 +0000</lastBuildDate>
    <item>
      <title>BREW-dvc-CVE-2026-54590 — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a le…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-dvc-cve-2026-54590</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: dvc&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: dvc&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-dvc-cve-2026-54590</guid>
    </item>
    <item>
      <title>CVE-2026-54590 — AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-54590</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; ronf asyncssh&lt;/p&gt;
&lt;p&gt;AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing later expansion in _expand_val and Path(filename).expanduser() to escape the intended authorized-keys directory. This issue is fixed in version 2.23.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; ronf asyncssh&lt;/p&gt;
&lt;p&gt;AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing later expansion in _expand_val and Path(filename).expanduser() to escape the intended authorized-keys directory. This issue is fixed in version 2.23.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-54590</guid>
    </item>
    <item>
      <title>GHSA-qr67-gv47-xwwh — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a le…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qr67-gv47-xwwh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asyncssh&lt;/p&gt;
&lt;p&gt;**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
  2.23.0 guard that sanitises the SSH username before `%u` substitution
  in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
  leading `~` (or `${ENV}`), both of which are re-introduced by later
  expansion and reach the file open — defeating the guard.&lt;/p&gt;
&lt;p&gt;**Affected:** asyncssh 2.23.0 and current `develop` (commit `a60f863`,
  HEAD on 2026-05-29).&lt;/p&gt;
&lt;p&gt;## Summary
  The fix for CVE-2026-45309 added a guard in
  `SSHServerConfig._set_tokens` (`asyncssh/config.py:715-716`) that
  rejects an SSH username containing `/`, `\`, or equal to `..`, before
  it is substituted for the `%u` token in `AuthorizedKeysFile`:&lt;/p&gt;
&lt;p&gt;if self._user == &amp;#39;..&amp;#39; or &amp;#39;/&amp;#39; in self._user or &amp;#39;\\&amp;#39; in self._user:
          raise IllegalUserName(&amp;#39;Unsafe username substitution&amp;#39;)&lt;/p&gt;
&lt;p&gt;However, the `%u`-substituted value is subsequently passed through
  environment-variable expansion (`_expand_val`, `config.py:145-149` —
  token expansion then env expansion) and, at file-open time, through
  `expanduser()` (`read_authorized_keys` → `read_file` →
  `open(Path(filename).expanduser())`, `auth_keys.py:348` →
  `misc.py:290`). Both re-introduce the path control the guard was meant
  to remove, so a username that contains no `/`/`\` can still cause the
  server to read an authorized-keys file outside the intended per-user
  directory.&lt;/p&gt;
&lt;p&gt;The client-supplied username reaches this path pre-authentication:
  `_process_userauth_request` takes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qr67-gv47-xwwh</guid>
    </item>
  </channel>
</rss>
