TL;DR
wolfSSL has released wolfSSH 1.6.0 to fix five security flaws in its lightweight SSH library. The most serious of these wolfSSH vulnerabilities, CVE-2026-16516, scores 9.0 on CVSS 4.0 and can let a man-in-the-middle attacker pass off a forged server key. All five affect wolfSSH 1.5.0 and earlier.
- Total: 5 CVEs
- Severity: 1 Critical Β· 1 High Β· 3 Medium
- Actively exploited: None confirmed
- Highest severity: 9.0 (Critical Β· CVSSv4) β CVE-2026-16516
- Action: Apply the latest security updates now
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-16516 | 9 | ECDSA host key curve not validated against negotiated algorithm | 1.6.0 | Not exploited |
| CVE-2026-83540 | 7.7 | d on Windows race condition leading to logon token reused across connections | 1.6.0 | Not exploited |
| CVE-2026-84897 | 6.9 | server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion | 1.6.0 | Not exploited |
| CVE-2026-81535 | 6.3 | SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check | 1.6.0 | Not exploited |
| CVE-2026-83742 | 5.3 | wstrncat() unsigned integer underflow leads to an off-by-one null write in on non-Windows platforms | 1.6.0 | Not exploited |
Why It Matters
wolfSSH is built for embedded devices, IoT products and other constrained systems. Vendors often ship it deep inside firmware, where updates arrive slowly. As a result, flaws in the library can linger in products long after a fix exists.
Together, these wolfSSH vulnerabilities span both the client and server sides of the library. The bugs touch key exchange, login handling, port forwarding and SFTP. The CVE records list exploitation status as unknown, and no public proof-of-concept has been confirmed.
How the Attacks Work
Host Key Curve Not Checked (CVE-2026-16516)
During key exchange, a wolfSSH client reads the server’s ECDSA host key. However, it “does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated.” An attacker in the middle can swap in a key on a different curve that they control. Signature checks then pass. The attack also needs a lax key-check callback, such as trust-on-first-use.
Windows Login Poisoning (CVE-2026-83540)
This bug, rated 7.7, hits only the Windows port of the wolfSSHd server. The server does not release the Windows logon token from one connection before the next. Consequently, “a less privileged user with a valid account on the server can exploit this to force a login as a more privileged user.” wolfSSL’s own testing found the flaw.
Pre-Authentication CPU Drain (CVE-2026-84897)
A wolfSSH server accepts certain key exchange messages that only a server should send. An unauthenticated client can abuse this to make the server test very large primes. That burns CPU before login and confuses the server’s role in the handshake.
Forwarding and SFTP Bugs
CVE-2026-81535 lets a malicious peer open unlimited forwarding channels that the application never authorized. The client also fails to check those channels against the forwards it actually requested, as RFC 4254 requires. Meanwhile, CVE-2026-83742 allows a logged-in user to write a single null byte past a stack buffer with a crafted SFTP path, which may crash the process.
Affected Versions
The affected ranges vary by flaw:
- CVE-2026-16516: all versions through 1.5.0
- CVE-2026-83540: 1.4.15 through 1.5.0, Windows wolfSSHd only
- CVE-2026-84897: 1.2.0 through 1.5.0
- CVE-2026-81535: 1.4.8 through 1.5.0, builds with forwarding enabled
- CVE-2026-83742: 1.4.11 through 1.5.0, non-Windows platforms
Patch and Mitigation Steps
Upgrade to the wolfSSH 1.6.0 release, which closes all five wolfSSH vulnerabilities. Device makers should rebuild and ship firmware with the new library.
Until then, use a strict host key check in client code rather than trust-on-first-use. In addition, disable port forwarding if you do not need it. Builds that turn off Diffie-Hellman group exchange are not exposed to CVE-2026-84897.
Several outside researchers reported the bugs, including GitHub user afldl, Asif Nadaf and an academic team led by Syed Rafiul Hussain.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!