CVE-2023-46445: Asyncssh Project Asyncssh
Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
Affected products
- Asyncssh Project Asyncssh: before 2.14.1 (fixed in 2.14.1)
Published 2023-11-14. Last modified 2026-06-17.