ECDSA Host Key Vulnerability in wolfSSH Software by wolfSSL
CVE-2026-16516
9CRITICAL
What is CVE-2026-16516?
The wolfSSH software contains a vulnerability where the ECDSA curve identifier in a key exchange reply is not properly validated. This oversight allows an attacker in an active man-in-the-middle position to substitute a host key blob with a mismatched ECDSA curve. As the validation against the negotiated curve algorithm is bypassed, the substitution leads to the client mistakenly importing the host key on the incorrect curve, which can falsely pass signature verification. Proper security measures are necessary to mitigate exploitation risks, particularly in settings that employ lax public key validation methods, such as trust-on-first-use or algorithm-name matching.
Affected Version(s)
wolfSSH 0 <= 1.5.0
