Vulnerability in wolfSSH Client Key Exchange Messages by wolfSSL
CVE-2026-84897

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-84897?

In wolfSSL's wolfSSH, versions up to 1.5.0, an issue has been identified with server-side handling of Diffie-Hellman group exchange messages. The server fails to authenticate the legitimacy of messages sent by unauthenticated clients, allowing potential attackers to exploit this by sending specific key exchange messages. The vulnerability stems from the inadequate direction check in the IsMessageAllowedServer() function during the key exchange process. This oversight enables an attacker to negotiate a valid key exchange and, subsequently, produce a Diffie-Hellman key pair using the attacker's own parameters without appropriate validation. Consequently, this flaw could compromise the security of encrypted communications. Users should ensure they are running versions that have the corrective measures or disable certain configurations to mitigate this vulnerability.

Affected Version(s)

wolfSSH 1.2.0 <= 1.5.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdullah Al Ishtiaq, Kai Tu, Matthew Carter, Xiaotian Zhou, Ananna Rahman, Yilu Dong, Tianwei Yu, Ali Ranjbar, Syed Rafiul Hussain
.