PT-2026-107390 · Wolfssl · Wolfssh

CVE-2026-84897

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y
Name of the Vulnerable Software and Affected Versions wolfSSL wolfSSH versions 1.2.0 through 1.5.0
Description In the src/internal.c file, the server incorrectly accepts server-to-client Diffie-Hellman group exchange messages, specifically SSH MSG KEX DH GEX GROUP (31) and SSH MSG KEX DH GEX REPLY (33), from unauthenticated clients. This occurs because the IsMessageAllowedServer() function fails to apply a direction check to the key exchange message range when the peer is keying and no specific message is expected. Consequently, the server may execute the client-side handler DoKexDhGexGroup(), which processes attacker-supplied groups. In version 1.5.0, this involves performing two 8-round Miller-Rabin primality tests on values up to 8192 bits. Versions 1.2.0 through 1.4.22 enter the same client-role path without these primality tests. Builds that define WOLFSSH NO DH GEX SHA256, WOLFSSH NO DH, or NO SHA256 are not affected.
Recommendations Update wolfSSL wolfSSH to a version later than 1.5.0. As a temporary mitigation, define WOLFSSH NO DH GEX SHA256, WOLFSSH NO DH, or NO SHA256 during the build process to disable the affected functionality.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84897

Affected Products

Wolfssh