Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-16516— wolfSSH ECDSA host key curve not validated against negotiated algorithm

Quick assessment

Affected
wolfSSL Inc. wolfSSH
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

wolfSSH 未验证 KEXDH_REPLY 主机密钥 blob 中的 ECDSA 曲线标识符是否与密钥交换过程中协商的算法相匹配。在 函数(位于 src/internal.c 中),系统使用该 blob 的算法字符串通过 / 推导曲线,但未与协商确定的 进行比对;此外,RFC 5656 定义的曲线标识符字符串被 直接跳过丢弃,而非用于校验。主动网络中间人(MitM)攻击者可替换主机密钥 blob,使其包含不同的 ECDSA 曲线,导致客户端将密钥导入错误的曲线。由于攻击者控制替换曲线对应的私钥,签名验证仍会成功

CVSS 9.0 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-16516

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wolfSSH ECDSA host key curve not validated against negotiated algorithm
Source: CVE Program / CVE List V5
Vulnerability Description
wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via NameToId/wcPrimeForId without checking against the negotiated ssh->handshake->pubKeyId, and the RFC 5656 curve identifier string is discarded via GetSkip() rather than compared. An active network man-in-the-middle attacker can substitute a host key blob containing a different ECDSA curve, causing the client to import the key on the wrong curve. Because the attacker controls the private key for the substituted curve, signature verification passes. Exploitation requires an active MitM position and a lax public key check callback (e.g., TOFU, algorithm-name-only check, or fingerprint match against the parsed key).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL Inc. wolfSSH 0 ~ 1.5.0 -

II. Public POCs for CVE-2026-16516

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16516

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-16516 (1)

Vendor Advisories for CVE-2026-16516 (1)

Same Patch Batch · wolfSSL Inc. · 2026-10-07 · 4 CVEs total

CVE-2026-84897 6.9 MEDIUM wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated
CVE-2026-81535 6.3 MEDIUM wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorizat
CVE-2026-83742 5.3 MEDIUM wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-

IV. Related Vulnerabilities

V. Comments for CVE-2026-16516

No comments yet


Leave a comment