PT-2026-93998 · Pypi · Asyncssh

CVE-2026-62949

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AsyncSSH versions prior to 2.24.0
Description AsyncSSH is a Python package providing an asynchronous client and server implementation of the SSHv2 protocol. The software fails to validate the send pktsize value provided by a peer, allowing it to be set to zero. When channel data is processed by the SSHChannel. flush send buf() function, a value of zero causes a synchronous infinite loop that blocks the entire asyncio event loop. This occurs because the loop removes zero bytes without reducing the send window and contains no await point, making it impossible to interrupt via timeouts.
A malicious SSH server can trigger this state in a client via the SSH MSG CHANNEL OPEN CONFIRMATION message. Alternatively, an authenticated client can trigger it in a server via the SSH MSG CHANNEL OPEN message, which freezes all current and future connections handled by the process, resulting in total availability loss.
Recommendations Update AsyncSSH to version 2.24.0 or later. As a temporary mitigation, restrict access to the SSH server to trusted authenticated users to reduce the risk of a client-triggered freeze.

Exploit

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-KI90686
CVE-2026-62949
ECHO-6459-65B4-6F8C
GHSA-RW4J-R22C-9GC3
OPENSUSE-SU-2026:11851-1
OPENSUSE-SU-2026:21953-1
PYSEC-2026-4026

Affected Products

Asyncssh