<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[wolfSSL - Embedded SSL Library — wolfSSH 1.4.21 Released]]></title>
		<link>https://www.wolfssl.com/forums/topic2399-wolfssh-1421-released.html</link>
		<atom:link href="https://www.wolfssl.com/forums/feed-rss-topic2399.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in wolfSSH 1.4.21 Released.]]></description>
		<lastBuildDate>Thu, 23 Oct 2025 22:35:32 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[wolfSSH 1.4.21 Released]]></title>
			<link>https://www.wolfssl.com/forums/post8568.html#p8568</link>
			<description><![CDATA[<p><a href="https://www.wolfssl.com/products/wolfssh/">Version 1.4.21 of wolfSSH</a> is now available! This update includes a critical security fix, improved interoperability, and enhancements for embedded and hardware-backed key use cases.</p><p><strong>Security Updates</strong><br />This release addresses two security issues:<br /></p><ul><li><p><strong>CVE-2025-11625</strong>: Fixed a client-side host verification bypass that could expose credentials. (<a href="https://github.com/wolfSSL/wolfssh/pull/840">PR#840</a>)</p></li></ul><ul><li><p><strong>CVE-2025-11624</strong>: Fixed an SFTP server stack overflow triggered by malformed input. Thanks to Stanislav Fort of Aisle Research for the report</p></li></ul><p><strong>Feature Additions</strong><br /></p><ul><li><p><strong>TPM key authentication</strong> for hardware-based identity protection.</p></li></ul><ul><li><p><strong>ED25519 key generation</strong> support added to the API.</p></li></ul><ul><li><p><strong>Curve25519 alias compatibility</strong> with <span style="color: #188038">curve25519-sha256@libssh.org</span> for improved interoperability.</p></li></ul><ul><li><p><strong>Keyboard-interactive authentication</strong> can now be enabled at build time (<span style="color: #188038">--enable-keyboard-interactive</span>).</p></li></ul><ul><li><p><strong>AES-CBC</strong> is now disabled by default, shifting focus toward stronger default cipher suites.</p></li></ul><ul><li><p>Added <strong>Microchip ATSAMV71Q21B</strong> example with harmony filesystem integration.</p></li></ul><p>This version refines FATFS support, enhances user authentication handling, and improves SFTP and rekeying operations. Post quantum hybrid support was also touched up along with numerous Coverity findings, warning cleanups, and minor API consistency fixes.</p><p>Users of the wolfSSH client code or SFTP server should upgrade, particularly those relying on host verification.</p><p>If you have questions about any of the above, please contact us at <a href="mailto:facts@wolfssl.com">facts@wolfssl.com</a> or call us at +1 425 245 8247.</p><p><strong><a href="https://www.wolfssl.com/download/">Download </a>wolfSSL Now</strong></p>]]></description>
			<author><![CDATA[null@example.com (shizuka)]]></author>
			<pubDate>Thu, 23 Oct 2025 22:35:32 +0000</pubDate>
			<guid>https://www.wolfssl.com/forums/post8568.html#p8568</guid>
		</item>
	</channel>
</rss>
