Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-84897— wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion

Quick assessment

Affected
wolfSSL Inc. wolfSSH
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 在 wolfSSL wolfSSH 1.5.0 及更早版本中,当服务器从未经身份验证的客户端接收 SSH_MSG_KEX_DH_GEX_GROUP(31)和 SSH_MSG_KEX_DH_GEX_REPLY(33)服务器到客户端的 Diffie-Hellman 组交换消息时,会允许这些消息。 函数在密钥交换消息范围上未施加方向性检查:当对端处于密钥协商状态且没有预期特定消息时(即服务器在处理完客户端的 KEXINIT 之后的整个窗口期内所处的状态,因为此时没有设置 ),该函数会从期

CVSS 6.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84897

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion
Source: CVE Program / CVE List V5
Vulnerability Description
src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) when a server receives them from an unauthenticated client. IsMessageAllowedServer() applies no direction check to the key exchange message range: when the peer is keying and no particular message is expected, which is the state a server is in for the whole window after it processes the client's KEXINIT because nothing sets handshake->expectMsgId there, the function falls out of its expectation branch without a verdict and reaches a numeric bound that admits every message id from 30 through 34. A client that negotiates diffie-hellman-group-exchange-sha256 and then sends message 31 makes the server run the client-side handler DoKexDhGexGroup(), which validates the attacker-supplied group with two 8-round Miller-Rabin primality tests, one on p and one on (p-1)/2, on a value of up to 8192 bits. The handler then returns success: the server stores the attacker's prime and generator, generates a Diffie-Hellman key pair in the attacker's group, and sends the client-role message SSH_MSG_KEX_DH_GEX_INIT (32) back to the attacker. Published RFC 3526 safe primes are the worst-case input and cost the attacker nothing to obtain. The primality validation was added in 1.5.0; versions from 1.2.0 through 1.4.22 admit the same message and enter the same client-role path without the primality cost. Message 33 is admitted as well, but on a server it is rejected before any cryptography because no public key check callback is registered, so it carries no comparable cost. Builds that define WOLFSSH_NO_DH_GEX_SHA256, which is implied by WOLFSSH_NO_DH or NO_SHA256, are unaffected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y
Source: CVE Program / CVE List V5
Vulnerability Type
不完整的内部状态区分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL Inc. wolfSSH 1.2.0 ~ 1.5.0 -

II. Public POCs for CVE-2026-84897

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84897

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-84897 (2)

News Coverage for CVE-2026-84897 (1)

Same Patch Batch · wolfSSL Inc. · 2026-10-07 · 4 CVEs total

CVE-2026-16516 9.0 CRITICAL wolfSSH ECDSA host key curve not validated against negotiated algorithm
CVE-2026-81535 6.3 MEDIUM wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorizat
CVE-2026-83742 5.3 MEDIUM wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-

IV. Related Vulnerabilities

V. Comments for CVE-2026-84897

No comments yet


Leave a comment