CVE-2026-90623: andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validation
A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/sshconnection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be considered affected?
Deployments running cochise version 0.4.1 or earlier should be considered affected where they use the SSH host key handling code in src/cochise/ssh_connection.py.
Does exploitation require an authenticated account or local access?
No authentication or local access is indicated. The issue can be launched remotely, although exploitation requires high complexity.
How urgent is remediation given the available exploit information?
A public exploit is reported as available, but the vulnerability is rated low severity and difficult to exploit. The project was notified through an issue report and has not responded, so no vendor fix or workaround is provided in the available data.