CVE-2018-1000805: High severity Paramiko Paramiko vulnerability
Last updated 25 August 2025
Other sources
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
— Launchpad
Python Paramiko through versions 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5 and 1.17.6 is vulnerable to an authentication bypass in paramiko/authhandler.py. A remote attacker could exploit this vulnerability in paramiko SSH servers to execute arbitrary code.
Upstream Issue:
https://github.com/paramiko/paramiko/issues/1283
Upstream Patch:
https://github.com/paramiko/paramiko/commit/56c96a65
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-1000805.
What is the severity of CVE-2018-1000805?
The severity of CVE-2018-1000805 is high with a severity value of 8.8.
What is the affected software?
The affected software is Paramiko versions 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, and 1.17.6.
What is the impact of CVE-2018-1000805?
The impact of CVE-2018-1000805 is remote code execution (RCE).
How can I fix CVE-2018-1000805?
To fix CVE-2018-1000805, update Paramiko to version 2.4.2 or higher.