{"id":"ECHO-06e5-62cc-395f","summary":"This issue has been fixed to the best ability of the maintainers by adjusting\nhost key ordering to always use the default if the client has learned a hostkey\nmatching the best-preference algorithm. Fixes beyond this are considered to\nreduce overall security by the maintainers.\nhttps://security-tracker.debian.org/tracker/CVE-2020-14145\nhttps://docs.ssh-mitm.at/vulnerabilities/CVE-2020-14145.html\n","modified":"2026-09-15T00:57:48.951298664Z","published":"2025-08-29T01:37:14.147612Z","withdrawn":"2025-08-03T16:59:07.240Z","upstream":["CVE-2020-14145","GHSA-96g2-7cqx-5ggh"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2020-14145"}],"affected":[{"package":{"name":"openssh","ecosystem":"Echo","purl":"pkg:deb/echo/openssh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:9.2p1-2+deb12u6"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-06e5-62cc-395f.json"}}],"schema_version":"1.9.0"}