{"package":"paramiko","ecosystem":"pypi","latest_version":"5.0.0","description":"SSH2 protocol library","license":"LGPL-2.1","license_risk":"weak_copyleft","commercial_use_notes":"LGPL: dynamic linking from closed-source is OK; static linking triggers source disclosure.","homepage":"https://pypi.org/project/paramiko/","repository":"https://github.com/paramiko/paramiko","downloads_weekly":24259541,"health":{"score":89,"risk":"low","breakdown":{"maintenance":25,"popularity":20,"security":23,"maturity":15,"community":6,"popularity_floor":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":3,"critical":0,"high":0,"medium":1,"low":2,"details":[{"vuln_id":"CVE-2023-48795","severity":"medium","summary":"Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin","affected_versions":"<0.40.2|>=0.1.0,<0.17.0|>=2.5.0,<3.4.0|<0.0.0-20231218163308-9d2ee975ef9f|=2.10.0|=2.10.1|=2.10.2|=2.10.3|=2.10.4|=2.10.5|=2.10.6|=2.11.0|=2.11.1|=2.12.0|=2.5.0|=2.5.1|=2.6.0|=2.7.0|=2.7.1|=2.7.2|=2.8.0|=2.8.1|=2.9.0|=2.9.1|=2.9.2|=2.9.3|=2.9.4|=2.9.5|=3.0.0|=3.1.0|=3.2.0|=3.3.0|=3.3.1|=3.3.2","fixed_version":"0.0.0-20231218163308-9d2ee975ef9f","source":"osv","published_at":"2023-12-18T19:22:09Z"},{"vuln_id":"CVE-2026-44405","severity":"low","summary":"Paramiko rsakey.py allows the SHA-1 algorithm","affected_versions":"<=4.0.0|=0.1-bulbasaur|=0.1-charmander|=0.9-doduo|=0.9-eevee|=0.9-fearow|=0.9-gyarados|=0.9-horsea|=0.9-ivysaur|=1.0|=1.1|=1.10.0|=1.10.1|=1.10.2|=1.10.3|=1.10.4|=1.10.5|=1.10.6|=1.10.7|=1.11.0|=1.11.1|=1.11.2|=1.11.3|=1.11.4|=1.11.5|=1.11.6|=1.12.0|=1.12.1|=1.12.2|=1.12.3|=1.12.4|=1.13.0|=1.13.1|=1.13.2|=1.13.3|=1.13.4|=1.14.0|=1.14.1|=1.14.2|=1.14.3|=1.15.0|=1.15.1|=1.15.2|=1.15.3|=1.15.4|=1.15.5|=1.16.0|=1.16.1|=1.16.2|=1.16.3|=1.17.0|=1.17.1|=1.17.2|=1.17.3|=1.17.4|=1.17.5|=1.17.6|=1.18.0|=1.18.1|=1.18.2|=1.18.3|=1.18.4|=1.18.5|=1.2|=1.3|=1.3.1|=1.4|=1.5.1|=1.5.2|=1.5.4|=1.6|=1.6.1|=1.6.2|=1.6.3|=1.6.4|=1.7|=1.7.1|=1.7.2|=1.7.4|=1.7.5|=1.7.6|=1.7.7.1|=1.7.7.2|=1.8.0|=1.8.1|=1.9.0|=2.0.0|=2.0.1|=2.0.2|=2.0.3|=2.0.4|=2.0.5|=2.0.6|=2.0.7|=2.0.8|=2.0.9|=2.1.0|=2.1.1|=2.1.2|=2.1.3|=2.1.4|=2.1.5|=2.1.6|=2.10.0|=2.10.1|=2.10.2|=2.10.3|=2.10.4|=2.10.5|=2.10.6|=2.11.0|=2.11.1|=2.12.0|=2.2.0|=2.2.1|=2.2.2|=2.2.3|=2.2.4|=2.3.0|=2.3.1|=2.3.2|=2.3.3|=2.4.0|=2.4.1|=2.4.2|=2.4.3|=2.5.0|=2.5.1|=2.6.0|=2.7.0|=2.7.1|=2.7.2|=2.8.0|=2.8.1|=2.9.0|=2.9.1|=2.9.2|=2.9.3|=2.9.4|=2.9.5|=3.0.0|=3.1.0|=3.2.0|=3.3.0|=3.3.1|=3.3.2|=3.4.0|=3.4.1|=3.5.0|=3.5.1|=4.0.0","fixed_version":null,"source":"osv","published_at":"2026-05-06T00:31:33Z"},{"vuln_id":"CVE-2026-44405","severity":"low","summary":"Paramiko rsakey.py allows the SHA-1 algorithm","affected_versions":"<=4.0.0|=0.1-bulbasaur|=0.1-charmander|=0.9-doduo|=0.9-eevee|=0.9-fearow|=0.9-gyarados|=0.9-horsea|=0.9-ivysaur|=1.0|=1.1|=1.10.0|=1.10.1|=1.10.2|=1.10.3|=1.10.4|=1.10.5|=1.10.6|=1.10.7|=1.11.0|=1.11.1|=1.11.2|=1.11.3|=1.11.4|=1.11.5|=1.11.6|=1.12.0|=1.12.1|=1.12.2|=1.12.3|=1.12.4|=1.13.0|=1.13.1|=1.13.2|=1.13.3|=1.13.4|=1.14.0|=1.14.1|=1.14.2|=1.14.3|=1.15.0|=1.15.1|=1.15.2|=1.15.3|=1.15.4|=1.15.5|=1.16.0|=1.16.1|=1.16.2|=1.16.3|=1.17.0|=1.17.1|=1.17.2|=1.17.3|=1.17.4|=1.17.5|=1.17.6|=1.18.0|=1.18.1|=1.18.2|=1.18.3|=1.18.4|=1.18.5|=1.2|=1.3|=1.3.1|=1.4|=1.5.1|=1.5.2|=1.5.4|=1.6|=1.6.1|=1.6.2|=1.6.3|=1.6.4|=1.7|=1.7.1|=1.7.2|=1.7.4|=1.7.5|=1.7.6|=1.7.7.1|=1.7.7.2|=1.8.0|=1.8.1|=1.9.0|=2.0.0|=2.0.1|=2.0.2|=2.0.3|=2.0.4|=2.0.5|=2.0.6|=2.0.7|=2.0.8|=2.0.9|=2.1.0|=2.1.1|=2.1.2|=2.1.3|=2.1.4|=2.1.5|=2.1.6|=2.10.0|=2.10.1|=2.10.2|=2.10.3|=2.10.4|=2.10.5|=2.10.6|=2.11.0|=2.11.1|=2.12.0|=2.2.0|=2.2.1|=2.2.2|=2.2.3|=2.2.4|=2.3.0|=2.3.1|=2.3.2|=2.3.3|=2.4.0|=2.4.1|=2.4.2|=2.4.3|=2.5.0|=2.5.1|=2.6.0|=2.7.0|=2.7.1|=2.7.2|=2.8.0|=2.8.1|=2.9.0|=2.9.1|=2.9.2|=2.9.3|=2.9.4|=2.9.5|=3.0.0|=3.1.0|=3.2.0|=3.3.0|=3.3.1|=3.3.2|=3.4.0|=3.4.1|=3.5.0|=3.5.1|=4.0.0","fixed_version":null,"source":"osv","published_at":"2026-07-13T15:15:38.769945Z"}]},"versions":{"latest":"5.0.0","total_count":143,"recent":["2.10.2","2.10.3","2.10.4","2.10.5","2.10.6","2.11.0","2.11.1","2.12.0","3.0.0","3.1.0","3.2.0","3.3.0","3.3.1","3.3.2","3.4.0","3.4.1","3.5.0","3.5.1","4.0.0","5.0.0"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":0,"first_published":null,"last_published":"2026-05-09T18:28:50.295900Z","dependencies_count":4,"dependencies":["bcrypt>=3.2","cryptography>=3.3","invoke>=2.0","pynacl>=1.5"]},"github_stats":{"stars":9861,"forks":2078,"open_issues":1198,"is_archived":false,"pushed_at":"2026-08-29T20:45:26Z","subscribers_count":317},"bundle":null,"typescript":null,"known_issues":{"bugs_count":6,"bugs_severity":{"high":1,"medium":4,"low":1},"status_breakdown":{"fixed":4,"open":2},"link":"/api/bugs/pypi/paramiko?version=5.0.0","scope":"version","details":[{"title":"Paramiko Unsafe randomness usage may allow access to sensitive information","severity":"high","status":"fixed","affected_version":null,"fixed_version":"1.7.1-3","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0299"},{"title":"Paramiko rsakey.py allows the SHA-1 algorithm","severity":"medium","status":"open","affected_version":null,"fixed_version":null,"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44405"},{"title":"PYSEC-2018-19: advisory","severity":"medium","status":"fixed","affected_version":null,"fixed_version":"fa29bd8446c8eab237f5187d28787727b4610516","url":"https://github.com/paramiko/paramiko/commit/fa29bd8446c8eab237f5187d28787727b4610516"},{"title":"PYSEC-2008-8: advisory","severity":"medium","status":"fixed","affected_version":null,"fixed_version":"1.7.2","url":"http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch"},{"title":"Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin","severity":"medium","status":"fixed","affected_version":null,"fixed_version":"0.40.2","url":"https://github.com/warp-tech/russh/security/advisories/GHSA-45x7-px36-x8w8"}]},"historical_compromise":null,"recommendation":{"action":"safe_to_use","issues":[],"use_version":"5.0.0","version_hint":"Update to >= 0.0.0-20231218163308-9d2ee975ef9f to fix known vulnerabilities","summary":"paramiko@5.0.0 is safe to use (health: 89/100)","alternatives":[{"name":"asyncssh","reason":"asyncssh has an async API","builtin":false}]},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/pypi/paramiko","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/pypi/paramiko","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/pypi/paramiko","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate"},"_cache":"hit","_response_ms":0}