CVE-2026-44405
Low
Paramiko rsakey.py allows the SHA-1 algorithm
In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
Exploit probability
0.1%
Published
July 13, 2026
Required by
Not available
Last source change
July 13, 2026
02 / AFFECTED SOFTWARE
Affected packages
150 explicit affected versions
150 explicit affected versions
36 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2026-44405
View original source
In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
Open Source Vulnerabilities
GHSA-r374-rxx8-8654
View original source
In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
Open Source Vulnerabilities
PYSEC-2026-2858
View original source
In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44405.json
- https://github.com/paramiko/paramiko/commit/a4489456b6f65281e172380cc4826cee5e851dbb
- https://nvd.nist.gov/vuln/detail/CVE-2026-44405
- https://ostif.org/wp-content/uploads/2026/05/25-11-2415-REP_paramiko-security-audit_v1.1.pdf
- https://github.com/paramiko/paramiko
- https://github.com/advisories/GHSA-r374-rxx8-8654
- https://pypi.org/project/paramiko