CVE-2026-44405
Aliases:GHSA-r374-rxx8-8654PYSEC-2026-2858
Advisory lineage Upstream: 0 Downstream: 7
Awaiting Analysis
Published: 05 May 2026, 23:50
Last modified:06 May 2026, 12:54
Vulnerability Summary
Overall Risk (default)
low
14/100 CVSS Score
3.4 LOW
v3.1 (cve.org)
EPSS Score
0.11% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
05 May 2026, 23:50
Published
Vulnerability first disclosed
06 May 2026, 12:54
Last Modified
Vulnerability information updated
Description
In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
CVSS Metrics
- v3.1•LOW•Score: 3.4CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Trends
Current EPSS score: 0.11%• Percentile: 2%
Techniques & Countermeasures
- CWE-327•Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
Affected Systems
- paramiko•paramiko
< a4489456b6f65281e172380cc4826cee5e851dbb
- PyPI•paramiko
≤ 4.0.0
References (6)
- https://github.com/paramiko/paramiko/commit/a4489456b6f65281e172380cc4826cee5e851dbb
- https://ostif.org/wp-content/uploads/2026/05/25-11-2415-REP_paramiko-security-audit_v1.1.pdf
- https://nvd.nist.gov/vuln/detail/CVE-2026-44405
- https://github.com/paramiko/paramiko
- https://pypi.org/project/paramiko
- https://github.com/advisories/GHSA-r374-rxx8-8654