Skip to content

QuantumScan

paramiko/paramiko

paramiko/paramiko
78
risk score
50 findings · 30 files scanned

Paramiko SSH library contains 52 quantum-vulnerable cryptographic implementations including RSA, ECDSA, ECDH, and classical Diffie-Hellman primitives that will be broken by quantum computers. SHA-1 and MD5 are used in 10 critical locations, creating immediate collision attack risks. Migration to NIST-approved post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA) is essential for long-term security compliance.

Recent findingsView all findings →
FileAlgorithmSeverity
paramiko/sftp.py:161MD5critical
tests/agent.py:113RSA key ≤ 2048 bitscritical
tests/agent.py:104RSA key ≤ 2048 bitscritical
tests/conftest.py:132RSA key ≤ 2048 bitscritical
tests/test_packetizer.py:107SHA-1critical
tests/test_packetizer.py:25SHA-1critical
tests/test_packetizer.py:53SHA-1critical
tests/test_packetizer.py:83SHA-1critical
tests/test_util.py:25SHA-1critical
paramiko/__init__.py:115RSAhigh
Exposure by language
Python50 · 100%
Compliance mapping
DORA
Partial
NIS2
Gap
NIST PQC
Partial
Exports for compliance
Share read-only link

Anyone with this link can view the risk score and top findings — no sign-in required. Source code stays private.

https://quantumscan.io/en/share/1b7fc714-ff1d-4c23-bd09-c77182583997
Add a badge to your README

Show your project's post-quantum readiness in the README. The badge updates automatically after every new scan.

Preview

Post-Quantum Readiness
Markdown
[![Post-Quantum Readiness](https://quantumscan.io/api/badge/paramiko/paramiko.svg)](https://github.com/paramiko/paramiko)
HTML
<a href="https://github.com/paramiko/paramiko"><img src="https://quantumscan.io/api/badge/paramiko/paramiko.svg" alt="Post-Quantum Readiness" /></a>

Add badge to your README

Show your quantum-safety score directly on GitHub.

QuantumScan badge preview
[![QuantumScan](https://quantumscan.io/api/badge/paramiko/paramiko.svg)](https://quantumscan.io/en/scan/1b7fc714-ff1d-4c23-bd09-c77182583997)

Save your results & track future changes

Create a free account to get drift alerts, compliance PDF exports, and scan history.

  • Weekly drift alerts when new vulnerabilities appear
  • Track risk score over time across all your repos
  • Export DORA / NIS2 compliance PDF for auditors

Free forever for design partners · No credit card