wolfSSH 1.6.0 Fixes 5 Security Flaws Including Critical MITM Host Key Verification Bypass
wolfSSL released wolfSSH 1.6.0, fixing five flaws including a critical SSH host-key verification bypass.
wolfSSL published wolfSSH 1.6.0 on October 6, 2026, patching five vulnerabilities affecting versions through 1.5.0: one critical, one high, and three medium. Critical CVE-2026-16516 lets a man-in-the-middle replace the server ECDSA host key with a different curve so signature checks succeed, but only if the application uses a weak public-key-checking callback. High-severity CVE-2026-83540 affects Windows wolfSSHd 1.4.15 through 1.5.0, where shared logon tokens can give one authenticated user another account’s identity. The remaining flaws are unauthenticated Diffie-Hellman group-exchange CPU abuse (CVE-2026-84897), policy-bypass TCP forwarding (CVE-2026-81535), and an authenticated SFTP NUL overflow (CVE-2026-83742); 1.6.0 also enables strict key exchange and 2048-bit minimum RSA user keys.
- CVE-2026-16516 lets a MITM swap ECDSA host-key curves through wolfSSH 1.5.0.
- Exploitation needs a weak public-key callback, so not every client is exposed.
- CVE-2026-83540 can mix Windows logon tokens across concurrent wolfSSHd sessions.
- Other fixes cover DH group-exchange CPU abuse, unauthorized forwarding, and an SFTP overflow.
- Version 1.6.0 enables strict key exchange and requires 2048-bit RSA user keys.
Vulnerabilities mentionedAll →
- CVE-2026-165169.0—ECDSA host-key curve confusion in wolfSSHpublished · wolfSSL wolfSSH+3 related
- CVE-2026-835407.7—Login poisoning in Windows wolfSSHd (wolfSSH 1.4.15–1.5.0)published · wolfSSL wolfSSHd (Windows port of wolfSSH)
| CVE | Vulnerability | CVSS |
|---|
Full article535 words · extracted from cybersecuritynews.com · click to collapse
wolfSSL has released wolfSSH 1.6.0 to fix five security flaws, including a critical host key verification bypass that could let an attacker impersonate an SSH server.
Published on October 6, 2026, the update addresses Windows privilege escalation, unauthenticated key exchange abuse, unauthorized forwarding channels, and an SFTP memory corruption bug.
The release rates one flaw critical, one high, and three medium. The most serious issue, CVE-2026-16516, affects wolfSSH through version 1.5.0.
During SSH key exchange, the client failed to check whether the ECDSA curve inside the server’s host key matched the algorithm agreed upon for the connection. An attacker positioned between the client and server could replace that key with one using a different curve.
Because the attacker owns the replacement key’s private key, signature verification could still succeed. However, exploitation also requires a weak public-key-checking callback in the application.
This condition matters: the flaw does not mean every affected client automatically accepts an attacker’s key. wolfSSL credits researcher zhangph, known on GitHub as afldl, with reporting the issue.
The high-severity issue, CVE-2026-83540, affects wolfSSHd on Windows from versions 1.4.15 through 1.5.0. Concurrent connections shared an authentication context containing a Windows logon token.
Both password and public key authentication wrote to this shared token, creating a risk that a user with a valid account could receive another user’s login identity, including one with higher privileges. Non-Windows builds are unaffected.
CVE-2026-84897 concerns incorrect handling of Diffie-Hellman group exchange messages. A vulnerable server accepted messages intended only for a server, allowing an unauthenticated client to trigger client-side processing.
After selecting diffie-hellman-group-exchange-sha256, an attacker could submit a chosen group and force costly checks of whether its numbers are prime.
wolfSSH 1.6.0 Fixes 5 Security Flaws
The release notes describe roughly half a second of CPU work per 1 KB packet containing a 4096-bit prime. The message-handling flaw affects versions 1.2.0 through 1.5.0, while the expensive prime checks apply from 1.5.0. Builds using WOLFSSH_NO_DH_GEX_SHA256 are unaffected.
CVE-2026-81535 affects versions 1.4.8 through 1.5.0 built with –enable-fwd. The software accepted forwarded-tcpip channel requests without checking the application’s forwarding policy.
Clients also accepted channels for remote forwards they had never requested. A peer could therefore cause an endpoint to allocate buffers for forwarding channels that the application had not approved.
The fifth flaw, CVE-2026-83742, affects non-Windows builds from versions 1.4.11 through 1.5.0. Incorrect length calculations in wolfSSH_RealPath() could let a crafted SFTP path write a terminating NUL byte just beyond a stack buffer.
An authenticated attacker could corrupt nearby data and crash the process. Applications supplying an output buffer smaller than the input face additional exposure to an unbounded copy.
Administrators and developers should upgrade affected deployments to wolfSSH 1.6.0 and review the official release notes before rollout.
The update enables strict key exchange by default, adding protection against the Terrapin attack previously covered by Cyber Security News. It also requires RSA user authentication keys of at least 2048 bits and, by default, limits failed authentication attempts to six.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.