wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass
wolfSSL's wolfSSH 1.6.0 patches five flaws, including a critical ECDSA host-key authentication bypass.
wolfSSL released wolfSSH 1.6.0 on October 6, 2026, fixing five vulnerabilities in versions through 1.5.0. CVE-2026-16516 (CVSS v4 9.0) lets an active man-in-the-middle attacker bypass ECDSA host-key checks when a permissive validation callback is used. CVE-2026-83540 (CVSS 7.7) can let a lower-privileged Windows wolfSSHd user reuse another user's logon token. Three medium issues cover Diffie-Hellman CPU exhaustion (CVE-2026-84897), unauthorized TCP forwarding (CVE-2026-81535), and a one-byte SFTP path overflow (CVE-2026-83742). The release also enables strict key exchange by default against the Terrapin attack (CVE-2023-48795).