wolfSSH v1.6.0 Release

wolfSSH v1.6.0 is now available. This release has five vulnerability fixes, strict key exchange enabled by default, ML-DSA host keys and user authentication, and the largest hardening pass wolfSSH has had. Several defaults have changed, so please read the Behavior Changes section before upgrading. See the ChangeLog.md for the full list.

Vulnerabilities

This release addresses five CVEs: one critical, one high, and three medium.

  • [Critical] CVE-2026-16516: The client did not check that the ECDSA curve in a server’s host key blob matched the negotiated algorithm. A man-in-the-middle could substitute a key on a different curve and pass verification. This also requires a lax public key check callback. It affects versions through 1.5.0. Thanks to zhangph (afldl).
  • [High] CVE-2026-83540: wolfSSHd on Windows shared one authentication context and logon token across concurrent connections. As a result, a user with a valid account could end up logged in as another, more privileged user. Non-Windows builds are unaffected. It affects 1.4.15 through 1.5.0 and was found by internal testing.
  • [Medium] CVE-2026-84897: A server accepted the DH GEX messages that only a server sends from an unauthenticated client. This let the client force expensive primality testing of an attacker-chosen group. It affects 1.2.0 through 1.5.0. Thanks to Abdullah Al Ishtiaq, Kai Tu, Matthew Carter, Xiaotian Zhou, Ananna Rahman, Yilu Dong, Tianwei Yu, Ali Ranjbar, and Syed Rafiul Hussain.
  • [Medium] CVE-2026-81535: With –enable-fwd, forwarded-tcpip channel opens bypassed the forwarding policy callback. A client also accepted these opens for forwards it never requested. It affects 1.4.8 through 1.5.0. Thanks to zhangph (afldl).
  • [Medium] CVE-2026-83742: A length wrap in wolfSSH_RealPath() let a crafted SFTP path write a NUL byte past the end of a stack buffer. It requires an authenticated session and affects 1.4.11 through 1.5.0 on non-Windows builds. Thanks to Asif Nadaf.

All wolfSSH users should upgrade. Users of wolfSSHd on Windows, and client applications with permissive public key check callbacks, should treat this as urgent.

Behavior Changes

  • v1.6.0 tightens many defaults. Changes most likely to affect existing applications:
  • wolfSSL must be built with –enable-wolfssh.
  • Strict KEX (the Terrapin mitigation) is on by default. You can opt out with wolfSSH_CTX_SetStrictKex().
  • The DH group exchange minimum is now 2048 bits. RSA user authentication keys must also be at least 2048 bits.
  • The “none” cipher and MAC require –enable-none-cipher.
  • The server disconnects after 6 failed authentication attempts. This is configurable with wolfSSH_CTX_SetMaxAuthAttempts().
  • Applications must now drain stderr. Ignoring WS_EXTDATA will exhaust the channel window.
  • A peer’s channel EOF is now reported as WS_EOF. Send your own with wolfSSH_ChannelSendEof().
  • wolfSSH_shutdown() may return WS_WANT_WRITE. Call it again until it completes.
  • Forwarding is stricter. forwarded-tcpip opens require a fwdCb, and the client refuses opens that don’t match a registered forward.
  • wolfSSHd changes:
    • StrictModes is enforced by default.
    • LoginGraceTime defaults to 120 seconds.
    • Sessions use a 022 umask.
    • Match is limited to User and Group.

New Features

  • Strict key exchange, with wolfSSH_GetStrictKexNegotiated().
  • ML-DSA-44, -65, and -87 host keys and user authentication, including X.509 and composite variants.
  • OpenSSH certificate user authentication in wolfSSHd (–enable-ossh-certs).
  • TPM-resident host keys, including X.509 host certificates.
  • Host keys from the Windows certificate store.
  • Builds with neither RSA nor ECDSA, such as Ed25519 only.
  • Client-side remote port forwarding.
  • SFTP session confinement with wolfSSH_SFTP_SetConfinePath().
  • Independent cipher and MAC negotiation in each direction.
  • Per-channel stderr flow control.
  • RFC 4254 half-close support.
  • Application-driven channels.
  • New wolfSSHd options:
    • PubkeyAuthentication.
    • prohibit-password and forced-commands-only for PermitRootLogin.
    • %u/%h expansion in AuthorizedKeysFile.
  • make sbom targets for CycloneDX and SPDX output.

Improvements and Fixes

This release has well over a hundred fixes, many from static analysis, fuzzing, and external audits. Highlights:

  • Validation of peer DH and ECDH public keys.
  • Bounded KEXINIT parsing, which closes a pre-auth CPU DoS.
  • Constant-time RSA verification.
  • Log injection sanitization.
  • SCP symlink hardening.
  • Per-session SFTP handle tracking and limits.
  • Zeroization of secrets.
  • A fix for a wolfSSHd user enumeration timing oracle.
  • Fixes for several fail-open wolfSSHd Match defects.
  • Corrected SFTP and SCP behavior across rekeys and on Windows, Zephyr, and Harmony.
  • FIPS wolfSSL fixes for DH-GEX and agent RSA signing.

Thanks to everyone who reported issues this cycle.

If you have questions about any of the above, please contact us at facts@wolfssl.com or call us at +1 425 245 8247.

Download wolfSSL Now