Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.0

CVE-2026-16516: wolfSSH may accept forged host key with wrong curve

CVE-2026-16516 · published 3 days ago
Summary

wolfSSH can be tricked into using a host key that uses a different elliptic curve than the one agreed during the connection. An attacker who can intercept the network and replace the key can make the client accept a signature that looks valid, letting the attacker impersonate the server. To protect yourself, ensure you use strict server authentication checks and avoid relying only on simple fingerprint matches or trust-on-first-use policies.

What to do
  • Update wolfssl inc. wolfssh to version 1.6.0.
Affected software
VendorProductAffected versions
wolfssl inc. wolfssh <= 1.5.0
Fix: upgrade to 1.6.0
Original advisory text
wolfSSH ECDSA host key curve not validated against negotiated algorithm
wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via NameToId/wcPrimeForId without checking against the negotiated ssh->handshake->pubKeyId, and the RFC 5656 curve identifier string is discarded via GetSkip() rather than compared. An active network man-in-the-middle attacker can substitute a host key blob containing a different ECDSA curve, causing the client to import the key on the wrong curve. Because the attacker controls the private key for the substituted curve, signature verification passes. Exploitation requires an active MitM position and a lax public key check callback (e.g., TOFU, algorithm-name-only check, or fingerprint match against the parsed key).
Fix within
Internet-facing 60 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker partial control
Severity
9.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-345Insufficient Verification of Data Authenticity
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-16516 · MITRE
Track software like this
Free during beta