๐Ÿ” CVE Alert

CVE-2026-90623

LOW 3.7

andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validation

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-295 CWE-287
Vendor andreashappe
Product cochise
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for andreashappe cochise

Be the first to know when new low vulnerabilities affecting andreashappe cochise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

andreashappe / cochise
0.4.0 0.4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/403205 vuldb.com: https://vuldb.com/vuln/403205/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90623 vuldb.com: https://vuldb.com/submit/914815 github.com: https://github.com/andreashappe/cochise/issues/13 github.com: https://github.com/andreashappe/cochise/

Credits

๐Ÿ” ez-lbz (VulDB User) VulDB CNA Team