CVE-2026-44405
Aliases:GHSA-r374-rxx8-8654PYSEC-2026-2858DEBIAN-CVE-2026-44405CGA-36vh-xwgr-5wfvCGA-48wr-qmxq-v34gCGA-4jgq-xfmm-vf8qCGA-585c-p9v5-cr36CGA-6873-74c5-4wj7CGA-6jmp-rmjg-87c9CGA-7mf3-6vv2-p8w3CGA-9cm4-pvq3-cw7hCGA-9hf6-24v6-vv3xCGA-9hxv-grwr-8g24CGA-cwg4-v2cx-q43hCGA-fq96-7x6w-m92fCGA-g263-wjxr-3qhhCGA-hcwh-x2c2-9qwvCGA-hh32-wg96-h3hvCGA-j338-xvgx-6p67CGA-m96m-g77r-47c5CGA-mjwc-rg4w-86jhCGA-pfxc-mgrg-pc37CGA-23qr-w8g8-4r84CGA-26h3-3hgj-wj5pCGA-29w4-f642-jp86CGA-2f64-5v5v-793wCGA-2vvx-8jxh-22w5CGA-36q6-fp2j-jv8xCGA-3h9m-4jm8-jh85CGA-3mw2-wmpj-r8pcCGA-54j6-69g8-gmw7CGA-5vpw-7978-3f44CGA-6fj7-2g5g-rhqxCGA-6qcx-whrg-34mqCGA-77pp-qcpj-756hCGA-7g3f-m65g-x783CGA-7p7x-xxch-r9rcCGA-8438-7g28-gcxrCGA-87rm-q7r7-p93cCGA-8h35-g44j-fc4hCGA-8jgj-rmcj-q8g2CGA-92hc-p9f4-mh34CGA-9j8f-9234-m6hmCGA-9rrx-3m3f-rvmvCGA-c83f-697c-63qfCGA-cm8q-j56h-x55cCGA-fhgx-cp9v-pxmwCGA-fjhh-m5qp-jgffCGA-fp32-7pc3-grfjCGA-fpxf-hch7-pm4cCGA-ggvf-6p4h-r73vCGA-hhhc-j8fc-4675CGA-hx8v-gqrf-9gvmCGA-j5xw-j74x-vm9jCGA-jm53-c8qr-5392CGA-jprv-cr4f-v384CGA-jrvp-c3gc-923hCGA-m8qq-5mq7-c4xrCGA-mpqg-mpp4-g5wgCGA-p8jv-4q39-87hqCGA-q3jf-48pj-5fwvCGA-qc2h-pwxg-v54hCGA-qcw8-9p68-65xxCGA-qhc2-x673-qp9vCGA-qhvq-g3xj-r8vjCGA-qm8x-v793-g93fCGA-qw4q-m3p6-vr33CGA-r635-p998-4hxhCGA-r9x8-f687-v6w2CGA-rhfh-r8h4-w64cCGA-rq9r-rqwg-9cm4CGA-rqw9-6mp3-v837CGA-rr7f-xhgr-xqqjCGA-vjqf-7j27-8cvrCGA-w5c3-v3x8-8v85CGA-wc75-x559-rf6xCGA-wcrw-p44p-3qvxCGA-x52r-qvxf-xvc3CGA-x7mp-7wrc-98q7CGA-xmmq-vw96-g9w9CGA-xwgj-r9g7-wx53CGA-949f-xc7m-rgjj
Advisory lineage Upstream: 0 Downstream: 7
Awaiting Analysis
Published: 05 May 2026, 23:50
Last modified:06 May 2026, 12:54
Vulnerability Summary
Overall Risk (default)
low
14/100 CVSS Score
3.4 LOW
v3.1 (cve.org)
EPSS Score
0.11% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
05 May 2026, 23:50
Published
Vulnerability first disclosed
06 May 2026, 12:54
Last Modified
Vulnerability information updated
Description
In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
CVSS Metrics
- v3.1•LOW•Score: 3.4CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Trends
Current EPSS score: 0.11%• Percentile: 2%
Techniques & Countermeasures
- CWE-327•Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
Affected Systems
- chainguard•airflow-2
all
- chainguard•airflow-3
< 3.2.1-r2
- chainguard•authentik-2025.12
all
- chainguard•authentik-2026.2
all
- chainguard•authentik-2026.5
< 2026.5.6-r13
- chainguard•authentik-fips-2025.12
all
- chainguard•authentik-fips-2026.2
all
- chainguard•authentik-fips-2026.5
< 2026.5.6-r14
- chainguard•az
< 2.90.0-r0
- chainguard•datadog-agent-7.71-core-integrations
< 7.71.2-r21
- chainguard•datadog-agent-7.72-core-integrations
< 7.72.4-r21
- chainguard•datadog-agent-7.73-core-integrations
all
- chainguard•datadog-agent-7.74-core-integrations
< 7.74.1-r15
- chainguard•datadog-agent-7.75-core-integrations
all
- chainguard•datadog-agent-7.76-core-integrations
all
- chainguard•datadog-agent-7.77-core-integrations
< 7.77.3-r7
- chainguard•datadog-agent-7.78-core-integrations
< 7.78.4-r18
- chainguard•datadog-agent-7.79-core-integrations
< 7.79.2-r3
- chainguard•datadog-agent-fips-7.71-core-integrations
all
- chainguard•datadog-agent-fips-7.72-core-integrations
all
- chainguard•datadog-agent-fips-7.73-core-integrations
all
- chainguard•datadog-agent-fips-7.74-core-integrations
< 7.74.1-r26
- chainguard•datadog-agent-fips-7.75-core-integrations
< 7.75.4-r5
- chainguard•datadog-agent-fips-7.76-core-integrations
< 7.76.3-r35
- chainguard•datadog-agent-fips-7.77-core-integrations
all
- chainguard•datadog-agent-fips-7.78-core-integrations
< 7.78.4-r17
- chainguard•datadog-agent-fips-7.79-core-integrations
< 7.79.2-r2
- chainguard•datadog-agent-fips-7.80-core-integrations
< 7.80.4-r2
- chainguard•duplicity
< 3.0.7-r4
- chainguard•keep-api
< 0.51.0-r6
- chainguard•keep-api-fips
< 0.51.0-r6
- chainguard•nemo
< 2.7.3-r2
- chainguard•openstack-nova-2026.1
< 33.0.1_git20260616-r0
- chainguard•pgadmin4
< 9.14-r2
- chainguard•py3.11-paramiko
< 5.0.0-r0
- chainguard•py3.12-paramiko
< 5.0.0-r0
- chainguard•py3.13-paramiko
< 5.0.0-r0
- chainguard•superset-5.0
< 5.0.0-r32
- chainguard•superset-5.0-iamguarded-compat
all
- chainguard•superset-6.0
< 6.0.0-r11
- chainguard•superset-fips-6.1
< 6.1.0-r5
- wolfi•airflow-3
< 3.2.1-r2
- wolfi•az
< 2.90.0-r0
- wolfi•datadog-agent-7.72-core-integrations
< 7.72.4-r21
- wolfi•datadog-agent-7.73-core-integrations
all
- wolfi•datadog-agent-7.74-core-integrations
< 7.74.1-r15
- wolfi•datadog-agent-7.75-core-integrations
all
- wolfi•datadog-agent-7.76-core-integrations
all
- wolfi•datadog-agent-7.77-core-integrations
< 7.77.3-r7
- wolfi•datadog-agent-7.78-core-integrations
< 7.78.4-r18
Showing first 50 affected entries in server-rendered view.
References (8)
- https://github.com/paramiko/paramiko/commit/a4489456b6f65281e172380cc4826cee5e851dbb
- https://ostif.org/wp-content/uploads/2026/05/25-11-2415-REP_paramiko-security-audit_v1.1.pdf
- https://nvd.nist.gov/vuln/detail/CVE-2026-44405
- https://github.com/paramiko/paramiko
- https://pypi.org/project/paramiko
- https://github.com/advisories/GHSA-r374-rxx8-8654
- https://security-tracker.debian.org/tracker/CVE-2026-44405
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44405.json