PT-2026-93998 · Pypi · Asyncssh
CVE-2026-62949
·
Published
2026-09-16
·
Updated
2026-10-01
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AsyncSSH versions prior to 2.24.0
Description
AsyncSSH is a Python package providing an asynchronous client and server implementation of the SSHv2 protocol. The software fails to validate the
send pktsize value provided by a peer, allowing it to be set to zero. When channel data is processed by the SSHChannel. flush send buf() function, a value of zero causes a synchronous infinite loop that blocks the entire asyncio event loop. This occurs because the loop removes zero bytes without reducing the send window and contains no await point, making it impossible to interrupt via timeouts.A malicious SSH server can trigger this state in a client via the
SSH MSG CHANNEL OPEN CONFIRMATION message. Alternatively, an authenticated client can trigger it in a server via the SSH MSG CHANNEL OPEN message, which freezes all current and future connections handled by the process, resulting in total availability loss.Recommendations
Update AsyncSSH to version 2.24.0 or later.
As a temporary mitigation, restrict access to the SSH server to trusted authenticated users to reduce the risk of a client-triggered freeze.
Exploit
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asyncssh