wolfSSH 1.6.0 Fixes 5 Security Flaws Including Critical MITM Host Key Verification Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


wolfSSL has released wolfSSH 1.6.0 to fix five security flaws, including a critical host key verification bypass that could let an attacker impersonate an SSH server.

Published on October 6, 2026, the update addresses Windows privilege escalation, unauthenticated key exchange abuse, unauthorized forwarding channels, and an SFTP memory corruption bug.

The release rates one flaw critical, one high, and three medium. The most serious issue, CVE-2026-16516, affects wolfSSH through version 1.5.0.

During SSH key exchange, the client failed to check whether the ECDSA curve inside the server’s host key matched the algorithm agreed upon for the connection. An attacker positioned between the client and server could replace that key with one using a different curve.

Because the attacker owns the replacement key’s private key, signature verification could still succeed. However, exploitation also requires a weak public-key-checking callback in the application.

This condition matters: the flaw does not mean every affected client automatically accepts an attacker’s key. wolfSSL credits researcher zhangph, known on GitHub as afldl, with reporting the issue.

The high-severity issue, CVE-2026-83540, affects wolfSSHd on Windows from versions 1.4.15 through 1.5.0. Concurrent connections shared an authentication context containing a Windows logon token.

Both password and public key authentication wrote to this shared token, creating a risk that a user with a valid account could receive another user’s login identity, including one with higher privileges. Non-Windows builds are unaffected.

CVE-2026-84897 concerns incorrect handling of Diffie-Hellman group exchange messages. A vulnerable server accepted messages intended only for a server, allowing an unauthenticated client to trigger client-side processing.

After selecting diffie-hellman-group-exchange-sha256, an attacker could submit a chosen group and force costly checks of whether its numbers are prime.

wolfSSH 1.6.0 Fixes 5 Security Flaws

The release notes describe roughly half a second of CPU work per 1 KB packet containing a 4096-bit prime. The message-handling flaw affects versions 1.2.0 through 1.5.0, while the expensive prime checks apply from 1.5.0. Builds using WOLFSSH_NO_DH_GEX_SHA256 are unaffected.

CVE-2026-81535 affects versions 1.4.8 through 1.5.0 built with –enable-fwd. The software accepted forwarded-tcpip channel requests without checking the application’s forwarding policy.

Clients also accepted channels for remote forwards they had never requested. A peer could therefore cause an endpoint to allocate buffers for forwarding channels that the application had not approved.

The fifth flaw, CVE-2026-83742, affects non-Windows builds from versions 1.4.11 through 1.5.0. Incorrect length calculations in wolfSSH_RealPath() could let a crafted SFTP path write a terminating NUL byte just beyond a stack buffer.

An authenticated attacker could corrupt nearby data and crash the process. Applications supplying an output buffer smaller than the input face additional exposure to an unbounded copy.

Administrators and developers should upgrade affected deployments to wolfSSH 1.6.0 and review the official release notes before rollout.

The update enables strict key exchange by default, adding protection against the Terrapin attack previously covered by Cyber Security News. It also requires RSA user authentication keys of at least 2048 bits and, by default, limits failed authentication attempts to six.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post wolfSSH 1.6.0 Fixes 5 Security Flaws Including Critical MITM Host Key Verification Bypass appeared first on Cyber Security News.