An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.
"https://github.com/pypa/advisory-database/blob/main/vulns/asyncssh/PYSEC-2023-237.yaml"