在 wolfSSH 1.5.0 版本(通过启用 编译选项构建)中, 文件中的 函数仅对 类型的通道打开操作施加了转发策略回调检查。然而,对于 类型的通道打开操作,却未进行任何授权检查,且对其数量没有上限限制。这使得恶意的 SSH 对端能够强制本端为应用程序从未授权批准的转发通道分配无限制的每通道缓冲区。此外,客户端也未按照 RFC 4254 第 7.2 节的要求,将 通道打开请求与其先前通过 请求注册的转发信息进行比对校验。因此,恶意的 SSH 服务端可以为客户端从未要求转发的地址和端口擅自打开通道转发。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wolfSSL Inc. | wolfSSH | 1.4.8 ~ 1.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16516 | 9.0 CRITICAL | wolfSSH ECDSA host key curve not validated against negotiated algorithm |
| CVE-2026-84897 | 6.9 MEDIUM | wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated |
| CVE-2026-83742 | 5.3 MEDIUM | wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non- |
No comments yet