CVE-2026-44405: Paramiko

Low severity, CVSS 3.4. EPSS: 0.1% chance of exploitation in the next 30 days.

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

Affected products

Published 2026-05-06. Last modified 2026-07-24.