# wolfSSH 1.6.0 patches 5 vulnerabilities incl. critical ECDSA host-key MITM (CVE-2026-16516) and Windows wolfSSHd auth-token reuse (CVE-2026-83540)

> wolfSSL released wolfSSH 1.6.0 on 2026-10-06 fixing five vulnerabilities in the embedded SSH library: an ECDSA host-key curve mismatch enabling man-in-the-middle (CVE-2026-16516, CVSS v4 9.0), a Windows wolfSSHd logon-token reuse privilege issue (CVE-2026-83540, 7.7), unauthenticated DH group-exchange CPU exhaustion (CVE-2026-84897, 6.9), unauthorized forwarded-tcpip channel opens (CVE-2026-81535, 6.3) and a one-byte stack overflow in wolfSSH_RealPath() (CVE-2026-83742, 5.3). No in-the-wild exploitation or public PoC is reported.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3044
- **ID:** TL-2026-3044
- **Severity:** CRITICAL (CVSS 9)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-16516, CVE-2026-83540, CVE-2026-84897, CVE-2026-81535, CVE-2026-83742

## Description

wolfSSH is wolfSSL's lightweight, embeddable SSH client/server library and also ships the wolfSSHd daemon. Version 1.6.0-stable (released 2026-10-06) fixes five CVEs published by the wolfSSL CNA on 2026-10-07. All affect releases up to and including 1.5.0.

CVE-2026-16516 (Critical, CVSS v4.0 9.0, CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N, CWE-345, CAPEC-475): wolfSSH did not verify that the ECDSA curve in the KEXDH_REPLY host-key blob matched the curve negotiated during key exchange. The curve is derived from the blob's algorithm string and the RFC 5656 curve identifier is skipped instead of compared. An active man-in-the-middle can substitute a host key on a different curve, sign the exchange with their own private key, and signature verification passes. Exploitation additionally requires a weak public-key-check callback in the application (trust-on-first-use, algorithm-name-only checks, or fingerprint matching against the parsed key). Affects all versions through 1.5.0 (src/internal.c). Reported by zhangph (GitHub afldl), tracked in issue #1012, fixed by PR #1022. CISA ADP SSVC: Exploitation none, Automatable no, Technical Impact partial.

CVE-2026-83540 (High, CVSS v4.0 7.7, CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N, CWE-287 and CWE-613, CAPEC-233): on the Windows port of wolfSSHd, a logon token from one authenticated connection was not released before a token was acquired for the next, and concurrent connections shared one authentication context. A low-privileged user with a valid account can end up logged in as a more privileged user, via both password and public-key authentication. Affected code is apps/wolfsshd/auth.c (SetupUserTokenWin, CheckPasswordWIN); introduced with the initial Windows port in 1.4.15, so 1.4.15-1.5.0 on Windows only. Found by internal wolfSSL testing; fixed by PR #1163 (each Windows wolfSSHd connection now gets its own authentication context plus a sanity close of the token). Workaround: restrict which accounts can connect; disabling public-key authentication alone does not help.

CVE-2026-84897 (Medium, CVSS v4.0 6.9, CWE-372/405/400, CAPEC-227): the server accepts the server-to-client DH group-exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) from an unauthenticated client. After negotiating diffie-hellman-group-exchange-sha256, a client sending message 31 makes the server run two Miller-Rabin primality tests on an attacker-supplied value of up to 8192 bits, then generate a key pair in the attacker's group. One ~1 KB packet costs roughly 0.48 s of single-core CPU at 4096 bits and ~5.8 s at 8192 bits, repeatable on every connection. Affects 1.2.0-1.5.0 (primality cost from 1.5.0). Builds defining WOLFSSH_NO_DH_GEX_SHA256 are unaffected. Fixed by PR #1221; found by an academic team (Abdullah Al Ishtiaq, Kai Tu, Matthew Carter, Xiaotian Zhou, Ananna Rahman, Yilu Dong, Tianwei Yu, Ali Ranjbar, Syed Rafiul Hussain). SSVC: Automatable yes.

CVE-2026-81535 (Medium, CVSS v4.0 6.3, CWE-862/863, CAPEC-130): with --enable-fwd, the channel-open handler applied the forwarding-policy callback only to direct-tcpip opens; forwarded-tcpip opens were accepted without authorization or a cap, so a malicious peer can force unbounded per-channel buffer allocation. Clients also failed to match incoming forwarded-tcpip opens against forwards registered via tcpip-forward (RFC 4254 7.2), letting a malicious server open channels for addresses and ports never requested. Affects 1.4.8-1.5.0; fixed by PRs #1059, #1148, #1220; reported by zhangph.

CVE-2026-83742 (Medium, CVSS v4.0 5.3, CWE-191/121/193, CAPEC-100): an unsigned integer underflow in wstrncat() (src/port.c), reached through wolfSSH_RealPath() (src/ssh.c), bounds each appended path component by remaining buffer space rather than buffer size. Once the path passes the halfway mark the length calculation wraps, and an authenticated attacker sending a crafted SFTP path writes one NUL byte past a stack buffer, which may corrupt an adjacent stack value and crash the process. Applications calling wolfSSH_RealPath() with an output buffer smaller than the input face an unbounded stack copy. Non-Windows only; affects 1.4.11-1.5.0; fixed by PR #1084; reported by independent researcher Asif Nadaf.

Version 1.6.0 also hardens the library: strict KEX (Terrapin, CVE-2023-48795 mitigation) enabled by default, minimum DH group-exchange size raised to 2048 bits, RSA authentication keys of at least 2048 bits required, failed authentication attempts limited to six by default, and StrictModes enforced for wolfSSHd. The changelog additionally lists wolfSSHd fixes for an auth bypass under WOLFSSH_ALLOW_USERAUTH_NONE, fail-open Match defects, PermitRootLogin handling of every UID 0 account, and a stack over-read in Windows pseudo-console resize.

None of the sources report active exploitation or a public PoC, and none of the five CVEs were found in the CISA KEV catalog text that could be read (the full catalog could not be read end to end); CISA ADP SSVC lists Exploitation: none for the four records fetched with it. Priority should go to internet-exposed wolfSSH clients with permissive host-key callbacks and to Windows wolfSSHd deployments.

## MITRE ATT&CK

- T1557 Adversary-in-the-Middle
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1134 Access Token Manipulation
- T1021.004 Remote Services: SSH
- T1499.004 Endpoint Denial of Service: Application or System Exploitation

## Sources

- [wolfSSH v1.6.0-stable release](https://github.com/wolfSSL/wolfssh/releases/tag/v1.6.0-stable)
- [wolfSSH ChangeLog (v1.6.0 section)](https://github.com/wolfSSL/wolfssh/blob/master/ChangeLog.md)
- [wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass (GBHackers)](https://gbhackers.com/wolfssh-patches-5-security-vulnerabilities/)
- [CVE-2026-16516 CVE record (wolfSSL CNA)](https://cveawg.mitre.org/api/cve/CVE-2026-16516)
- [CVE-2026-83540 CVE record (wolfSSL CNA)](https://cveawg.mitre.org/api/cve/CVE-2026-83540)
- [CVE-2026-84897 CVE record (wolfSSL CNA)](https://cveawg.mitre.org/api/cve/CVE-2026-84897)
- [CVE-2026-81535 CVE record (wolfSSL CNA)](https://cveawg.mitre.org/api/cve/CVE-2026-81535)
- [CVE-2026-83742 CVE record (wolfSSL CNA)](https://cveawg.mitre.org/api/cve/CVE-2026-83742)
- [wolfSSH issue #1012: ECDSA host key curve substitution](https://github.com/wolfSSL/wolfssh/issues/1012)
- [wolfSSH PR #1221: DH group exchange message handling fix](https://github.com/wolfSSL/wolfssh/pull/1221)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3044
