You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Critical] CVE-2026-16516. wolfSSH did not check that the ECDSA curve in a server's host key blob matched the negotiated algorithm, so a man-in-the-middle could substitute a key on another curve and pass verification with a private key of its own. Also requires a lax public key check callback. Affects through 1.5.0. Thanks to zhangph (GitHub afldl). Fixed in PR #1022, issue #1012
[High] CVE-2026-83540. wolfSSHd on Windows shared one authentication context, and the logon token stored in it, across concurrent connections, so a user with a valid account could end up logged in as another, more privileged user. Password and public key logins both wrote the shared token. Non-Windows builds are unaffected. Affects 1.4.15 through 1.5.0. Found by internal wolfSSL testing. Fixed in PR #1163
[Medium] CVE-2026-84897. A wolfSSH server accepted the DH group exchange messages only a server sends, SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33), from an unauthenticated client. A client that negotiated diffie-hellman-group-exchange-sha256 and sent message 31 made the server run the client-side handler, which primality-tests an attacker-chosen group of up to 8192 bits, about half a second of CPU per 1 KB packet for a 4096-bit prime, and then continue the key exchange in the client role. Affects 1.2.0 through 1.5.0; the primality cost applies from 1.5.0. Builds with WOLFSSH_NO_DH_GEX_SHA256 are unaffected. Thanks to Abdullah Al Ishtiaq, Kai Tu, Matthew Carter, Xiaotian Zhou, Ananna Rahman, Yilu Dong, Tianwei Yu, Ali Ranjbar and Syed Rafiul Hussain. Fixed in PR #1221
[Medium] CVE-2026-81535. With --enable-fwd, forwarded-tcpip channel opens were admitted without consulting the forwarding policy callback, and a client accepted them for forwards it never requested with tcpip-forward. A peer could make an endpoint allocate buffers for forwarding channels the application never authorized. Affects 1.4.8 through 1.5.0. Thanks to zhangph (GitHub afldl). Fixed in PR #1059, #1148, #1220
[Medium] CVE-2026-83742. wolfSSH_RealPath() bounded each path component it appended by the space left in the output buffer rather than by the buffer's size, so once an accumulated path passed the halfway mark the unsigned length computation in wstrncat() wrapped and the copy became effectively unbounded. A crafted SFTP path could then write a single terminating NUL one byte past the end of a stack buffer, corrupting an adjacent value and crashing the process. Requires an authenticated session, and affects non-Windows builds. An application calling the public wolfSSH_RealPath() with an output buffer smaller than its input is further exposed to an unbounded copy. Affects 1.4.11 through 1.5.0. Thanks to Asif Nadaf. Fixed in PR #1084
Notes
wolfSSH now requires wolfSSL built with --enable-wolfssh (WOLFSSL_WOLFSSH); a build without it stops with an #error. (PR #938)
WOLFSSH_DEFAULT_GEXDH_MIN is now a 2048-bit floor, so GEX fails with a 1024-bit-only server. (PR #1056)
An OpenSSH client now gets the 4096-bit group 16, at 5-8x the cost of group 14; WOLFSSH_NO_DH_GROUP16_SHA512 keeps group 14. (PR #1056)
Strict KEX is on by default; a non-KEX message in a strict first KEX ends the connection. Opt out with wolfSSH_CTX_SetStrictKex(). (PR #1271)
RSA user authentication keys must now be at least 2048 bits (WOLFSSH_RSA_MIN_KEY_BITS); shorter keys must be regenerated. (PR #1101)
A "none" cipher or MAC now requires --enable-none-cipher. (PR #1117)
The SetAlgoList*() setters now validate input and can return WS_INVALID_ALGO_ID; most no longer accept NULL. (PR #1117)
wolfSSH_CTX_SetWindowPacketSize() now returns WS_BAD_ARGUMENT for a window over 256 KB or a packet over MAX_PACKET_SZ. (PR #995)
The server now disconnects after 6 failed authentication attempts; change it with wolfSSH_CTX_SetMaxAuthAttempts(). (PR #1117, #1127)
A password-change user auth request is now refused without reaching userAuthCb. (PR #1049)
A WOLFSSH_USERAUTH_REJECTED from keyboard-interactive setup now ends the session; NO_FAILURE_ON_REJECTED is gone. (PR #1202)
Applications must now drain stderr. Ignoring WS_EXTDATA exhausts the channel window and deadlocks it. (PR #1054)
wolfSSH_stream_read() now fails on extended data for any channel but the first; use wolfSSH_ChannelIdReadExt(). (PR #1054)
wolfSSH_extended_data_read() now returns WS_BAD_ARGUMENT for a zero outSz or no open channel, never WS_INVALID_EXTDATA. (PR #1054)
A peer's channel EOF is now reported as WS_EOF, not answered; send your own with wolfSSH_ChannelSendEof(). (PR #1195, #982)
wolfSSH_ChannelExit() now keeps the channel, and the application's pointer, valid until WS_CHANNEL_CLOSED. (PR #1195)
wolfSSH_shutdown() now returns WS_WANT_WRITE while output is still queued; call it again until it completes. (PR #1217, #1219, #1252)
wolfSSH_get_fd() given a NULL session now returns -1, where non-Windows builds returned WS_BAD_ARGUMENT. (PR #1247)
WS_CallbackFwd must now return the allocated port for a port-0 WOLFSSH_FWD_REMOTE_SETUP, not WS_FWD_SUCCESS. (PR #1059)
forwarded-tcpip channel opens now require a fwdCb, as direct-tcpip opens do; without one they are refused. (PR #1059)
A client now refuses a forwarded-tcpip open matching no registered forward; opt out with wolfSSH_SetFwdRemoteMatch(). (PR #1148, #1220)
A client now refuses tcpip-forward and cancel-tcpip-forward with REQUEST_FAILURE, even with a fwdCb. (PR #1214)
A client now refuses a session channel open outright, per RFC 4254 section 6.1, ahead of any channelOpenCb. (PR #1224)
Each WOLFSSH_FWD_LOCAL_SETUP now gets a WOLFSSH_FWD_LOCAL_CLEANUP; a fwdCb must not free that state twice. (PR #1229)
SFTP SETSTAT and FSETSTAT now apply the attributes or answer SSH_FX_OP_UNSUPPORTED, not always SSH_FX_OK. (PR #1197)
On Windows, an SFTP open with CREAT but not TRUNC no longer truncates an existing file, and EXCL now fails on one. (PR #1173)
The wolfssh client no longer accepts -N. It was parsed but never read, so it is now a usage error rather than silently ignored. (PR #1162)
wolfSSHd enforces StrictModes by default and refuses unsafe host key or CA file modes; StrictModes no relaxes only authorized keys. (PR #1042)
wolfSSHd refuses a Match keyed on anything but User or Group, and Match User X Group Y now requires both. (PR #1026, #1027)
Without FPKI, wolfSSHd certificate auth now requires AuthorizedKeysFile; CA-only logins fail closed. (PR #1019)
wolfSSHd's LoginGraceTime now defaults to 120 seconds, not unlimited. (PR #950)
wolfSSHd now keeps a 022 umask (WOLFSSHD_DEFAULT_UMASK), so sessions no longer create world-writable files. (PR #1269)
New Features
Added strict key exchange, the Terrapin (CVE-2023-48795) mitigation, and wolfSSH_GetStrictKexNegotiated(). (PR #1271, #1295)
Added ML-DSA-44, -65 and -87 host keys and user auth, with X.509 and composite variants. (PR #1048, #1109, #1259, #1266)
Added OpenSSH certificate user authentication to wolfSSHd, behind --enable-ossh-certs. (PR #1060)
Added TPM-resident host keys, including X.509 host certificates, with wolfSSH_CTX_UseTpmHostKey(). (PR #1033, #1081)
Added host keys from the Windows certificate store, and wolfSSHd options to load keys and CAs from system stores. (PR #900)
Added support for builds with neither RSA nor ECDSA, such as Ed25519 only. (PR #1257, #1183)
Added client-side remote port forwarding with wolfSSH_FwdRemoteSetup() and wolfSSH_FwdRemoteCancel(), and portfwd -r. (PR #1066)
Added wolfSSH_SetFwdRemoteMatch() to match remote forwards on the port alone or not at all. (PR #1148)
Added wolfSSH_ReadCert_file() and related certificate loaders that detect PEM or DER from the content. (PR #1140, #1150)
Added SFTP session confinement with wolfSSH_SFTP_SetConfinePath(), separate from where a session starts; wolfSSHd sets none. (PR #1000, #1167)
Added per-channel stderr buffering with window flow control, and the wolfSSH_Channel*Ext() read and send functions. (PR #1054)
Added independent cipher and MAC negotiation for each direction. (PR #952)
Added a packet-count rekey trigger and wolfSSH_SetMsgHighwater(). (PR #963)
Added wolfSSH_RekeyPending(), which reports whether a key exchange is in flight. (PR #1260)