« Back to list

Wolfssl

Wolfssl Wolfssh: vulnerabilities and CVEs

Wolfssl Wolfssh has 4 published vulnerabilities, 4 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months4
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-84897Medium (6.9)——Oct 7, 2026
src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) when a server receives them from an…
CVE-2026-83742Medium (5.3)——Oct 7, 2026
Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of…
CVE-2026-83540High (7.7)——Oct 7, 2026
When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent…
CVE-2026-16516Critical (9)——Oct 7, 2026
wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services2
  2. T1068 Exploitation for Privilege Escalation1
  3. T1078 Valid Accounts1
  4. T1190 Exploit Public-Facing Application1
  5. T1499.004 Application or System Exploitation1
  6. T1557 Adversary-in-the-Middle1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Wolfssl