https://seclists.org/oss-sec/2026/q2/414: Security audit of Paramiko completed, fixes coming in 5.0 lease
Published May 5, 2026
·Updated
Affected Software
2 affected components
pypi/paramiko<5.0
pypi/cryptography
The vulnerability in CVE-2026-1234 is considered to have a medium severity level.
To fix CVE-2026-1234, update Paramiko to version 5.0 or later as it contains necessary security fixes.
CVE-2026-1234 affects all versions of Paramiko prior to version 5.0.
CVE-2026-1234 could potentially allow unauthorized remote access or data interception on vulnerable installations.
The fixes for CVE-2026-1234 are scheduled to be released in Paramiko version 5.0.