Junglewise Threat Intelligence

CVE-2026-44405: Paramiko use of broken SHA-1 algorithm in RSA key handling

CVE-2026-44405 · Severity: low · CVSS 3.4 · Published 2026-05-06

Technologies: Paramiko, paramiko (PyPI). Vendors: Paramiko, PyPI.

Executive brief

Paramiko, a widely used Python library for making secure SSH connections, was found to support the outdated and insecure SHA-1 hashing algorithm for RSA keys. While this does not directly expose user data, it relies on a cryptographic method that is increasingly vulnerable to modern cyberattacks. Organizations using affected versions should update to ensure their encrypted communications meet current security standards.

Technical details

A vulnerability in Paramiko's RSA key handling (specifically within rsakey.py and auth_handler.py) allows the continued use of the SHA-1 hashing algorithm. SHA-1 is considered cryptographically weak and susceptible to collision attacks. An attacker with adjacent network access could potentially exploit this reliance on broken cryptography to compromise the integrity of the SSH session, although the complexity is high (AC:H). The issue was identified during a security audit and addressed by removing SHA-1 support from RSA key handling in commit a448945.

Affected products

  • Paramiko Paramiko Through 4.0.0 before commit a448945

Timeline

  • 2026-05-05: disclosed
  • 2026-05-06: advisory: NVD publication date

References

Related threats