Skip to main content

Vendor/product archive

wolfssh / wolfssh CVEs

Beta · best-effort

7 CVEs tagged to wolfssh / wolfssh4 Critical, 0 High, 1 Medium, 2 Low, 0 Unrated.

CVE-2026-0930

Published Apr 20, 2026

Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-15382

Published Jan 6, 2026

A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input cont…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14942

Published Jan 6, 2026

wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping u…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11625

Published Oct 21, 2025

Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11624

Published Oct 21, 2025

Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smalle…

CVSS 1.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-2873

Published Mar 25, 2024

A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, res…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-32073

Published Jul 13, 2022

WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1