Skip to content
RequestGuard Vulnerabilities
Pricing

paramiko

SSH2 protocol library

PyPI latest 5.0.0 LGPL-2.1

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

5.0.0

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

6 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

6

Paramiko not properly checking authentication before processing other requests

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 2.0.8ECOSYSTEM: introduced 2.1.0; fixed 2.1.5ECOSYSTEM: introduced 2.2.0; fixed 2.2.3ECOSYSTEM: introduced 2.3.0; fixed 2.3.2ECOSYSTEM: introduced 2.4.0; fixed 2.4.1

Fixed versions: 2.0.8, 2.1.5, 2.2.3, 2.3.2, 2.4.1, 1.18.5, 1.17.6, fa29bd8446c8eab237f5187d28787727b4610516

Race Condition in Paramiko

Affected range

ECOSYSTEM: introduced 2.10.0; fixed 2.10.1ECOSYSTEM: introduced 2.9.0; fixed 2.9.3ECOSYSTEM: introduced 0; fixed 2.9.3; introduced 2.10.0; fixed 2.10.1

Fixed versions: 2.10.1, 2.9.3

Paramiko Authentication Bypass vulnerability

Affected range

ECOSYSTEM: introduced 2.4.0; fixed 2.4.2ECOSYSTEM: introduced 2.3.0; fixed 2.3.3ECOSYSTEM: introduced 2.2.0; fixed 2.2.4ECOSYSTEM: introduced 2.1.0; fixed 2.1.6ECOSYSTEM: introduced 1.5.1; fixed 2.0.9

Fixed versions: 2.4.2, 2.3.3, 2.2.4, 2.1.6, 2.0.9

Paramiko Unsafe randomness usage may allow access to sensitive information

Affected range

ECOSYSTEM: introduced 0; fixed 1.7.1-3ECOSYSTEM: introduced 0; fixed 1.7.2

Fixed versions: 1.7.1-3, 1.7.2