<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[wolfSSL - Embedded SSL Library — wolfSSH v1.6.0 Release]]></title>
		<link>https://www.wolfssl.com/forums/topic2581-wolfssh-v160-release.html</link>
		<atom:link href="https://www.wolfssl.com/forums/feed-rss-topic2581.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in wolfSSH v1.6.0 Release.]]></description>
		<lastBuildDate>Fri, 09 Oct 2026 18:29:57 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[wolfSSH v1.6.0 Release]]></title>
			<link>https://www.wolfssl.com/forums/post8947.html#p8947</link>
			<description><![CDATA[<p><a href="https://www.wolfssl.com/products/wolfssh/">wolfSSH v1.6.0</a> is now available. This release has five vulnerability fixes, strict key exchange enabled by default, ML-DSA host keys and user authentication, and the largest hardening pass wolfSSH has had. Several defaults have changed, so please read the Behavior Changes section before upgrading. See the <a href="https://github.com/wolfSSL/wolfssh/blob/master/ChangeLog.md">ChangeLog.md</a> for the full list.</p><p><span class="bbu"><strong>Vulnerabilities</strong></span><br />This release addresses five CVEs: one critical, one high, and three medium.</p><ul><li><p><strong>[Critical] CVE-2026-16516:</strong> The client did not check that the ECDSA curve in a server’s host key blob matched the negotiated algorithm. A man-in-the-middle could substitute a key on a different curve and pass verification. This also requires a lax public key check callback. It affects versions through 1.5.0. Thanks to zhangph (afldl).</p></li></ul><ul><li><p><strong>[High] CVE-2026-83540:</strong> wolfSSHd on Windows shared one authentication context and logon token across concurrent connections. As a result, a user with a valid account could end up logged in as another, more privileged user. Non-Windows builds are unaffected. It affects 1.4.15 through 1.5.0 and was found by internal testing.</p></li></ul><ul><li><p><strong>[Medium] CVE-2026-84897:</strong> A server accepted the DH GEX messages that only a server sends from an unauthenticated client. This let the client force expensive primality testing of an attacker-chosen group. It affects 1.2.0 through 1.5.0. Thanks to Abdullah Al Ishtiaq, Kai Tu, Matthew Carter, Xiaotian Zhou, Ananna Rahman, Yilu Dong, Tianwei Yu, Ali Ranjbar, and Syed Rafiul Hussain.</p></li></ul><ul><li><p><strong>[Medium] CVE-2026-81535:</strong> With –enable-fwd, forwarded-tcpip channel opens bypassed the forwarding policy callback. A client also accepted these opens for forwards it never requested. It affects 1.4.8 through 1.5.0. Thanks to zhangph (afldl).</p></li></ul><ul><li><p><strong>[Medium] CVE-2026-83742:</strong> A length wrap in wolfSSH_RealPath() let a crafted SFTP path write a NUL byte past the end of a stack buffer. It requires an authenticated session and affects 1.4.11 through 1.5.0 on non-Windows builds. Thanks to Asif Nadaf.</p></li></ul><p>All wolfSSH users should upgrade. Users of wolfSSHd on Windows, and client applications with permissive public key check callbacks, should treat this as urgent.</p><p><span class="bbu"><strong>Behavior Changes</strong></span><br /></p><ul><li><p>v1.6.0 tightens many defaults. Changes most likely to affect existing applications:</p></li></ul><ul><li><p>wolfSSL must be built with –enable-wolfssh.</p></li></ul><ul><li><p>Strict KEX (the Terrapin mitigation) is on by default. You can opt out with wolfSSH_CTX_SetStrictKex().</p></li></ul><ul><li><p>The DH group exchange minimum is now 2048 bits. RSA user authentication keys must also be at least 2048 bits.</p></li></ul><ul><li><p>The “none” cipher and MAC require –enable-none-cipher.</p></li></ul><ul><li><p>The server disconnects after 6 failed authentication attempts. This is configurable with wolfSSH_CTX_SetMaxAuthAttempts().</p></li></ul><ul><li><p>Applications must now drain stderr. Ignoring WS_EXTDATA will exhaust the channel window.</p></li></ul><ul><li><p>A peer’s channel EOF is now reported as WS_EOF. Send your own with wolfSSH_ChannelSendEof().</p></li></ul><ul><li><p>wolfSSH_shutdown() may return WS_WANT_WRITE. Call it again until it completes.</p></li></ul><ul><li><p>Forwarding is stricter. forwarded-tcpip opens require a fwdCb, and the client refuses opens that don’t match a registered forward.</p></li></ul><ul><li><p>wolfSSHd changes:<br /></p><ul><li><p>StrictModes is enforced by default.</p></li></ul><ul><li><p>LoginGraceTime defaults to 120 seconds.</p></li></ul><ul><li><p>Sessions use a 022 umask.</p></li></ul><ul><li><p>Match is limited to User and Group.</p></li></ul></li></ul><p><span class="bbu"><strong>New Features</strong></span><br /></p><ul><li><p>Strict key exchange, with wolfSSH_GetStrictKexNegotiated().</p></li></ul><ul><li><p>ML-DSA-44, -65, and -87 host keys and user authentication, including X.509 and composite variants.</p></li></ul><ul><li><p>OpenSSH certificate user authentication in wolfSSHd (–enable-ossh-certs).</p></li></ul><ul><li><p>TPM-resident host keys, including X.509 host certificates.</p></li></ul><ul><li><p>Host keys from the Windows certificate store.</p></li></ul><ul><li><p>Builds with neither RSA nor ECDSA, such as Ed25519 only.</p></li></ul><ul><li><p>Client-side remote port forwarding.</p></li></ul><ul><li><p>SFTP session confinement with wolfSSH_SFTP_SetConfinePath().</p></li></ul><ul><li><p>Independent cipher and MAC negotiation in each direction.</p></li></ul><ul><li><p>Per-channel stderr flow control.</p></li></ul><ul><li><p>RFC 4254 half-close support.</p></li></ul><ul><li><p>Application-driven channels.</p></li></ul><ul><li><p>New wolfSSHd options:<br /></p><ul><li><p>PubkeyAuthentication.</p></li></ul><ul><li><p>prohibit-password and forced-commands-only for PermitRootLogin.</p></li></ul><ul><li><p>%u/%h expansion in AuthorizedKeysFile.</p></li></ul></li></ul><ul><li><p>make sbom targets for CycloneDX and SPDX output.</p></li></ul><p><span class="bbu"><strong>Improvements and Fixes</strong></span><br />This release has well over a hundred fixes, many from static analysis, fuzzing, and external audits. Highlights:</p><ul><li><p>Validation of peer DH and ECDH public keys.</p></li></ul><ul><li><p>Bounded KEXINIT parsing, which closes a pre-auth CPU DoS.</p></li></ul><ul><li><p>Constant-time RSA verification.</p></li></ul><ul><li><p>Log injection sanitization.</p></li></ul><ul><li><p>SCP symlink hardening.</p></li></ul><ul><li><p>Per-session SFTP handle tracking and limits.</p></li></ul><ul><li><p>Zeroization of secrets.</p></li></ul><ul><li><p>A fix for a wolfSSHd user enumeration timing oracle.</p></li></ul><ul><li><p>Fixes for several fail-open wolfSSHd Match defects.</p></li></ul><ul><li><p>Corrected SFTP and SCP behavior across rekeys and on Windows, Zephyr, and Harmony.</p></li></ul><ul><li><p>FIPS wolfSSL fixes for DH-GEX and agent RSA signing.</p></li></ul><p>Thanks to everyone who reported issues this cycle.</p><p>If you have questions about any of the above, please contact us at <a href="mailto:facts@wolfssl.com">facts@wolfssl.com</a> or call us at +1 425 245 8247.</p><p><strong><a href="https://www.wolfssl.com/download/">Download</a> wolfSSL Now</strong></p>]]></description>
			<author><![CDATA[null@example.com (shizuka)]]></author>
			<pubDate>Fri, 09 Oct 2026 18:29:57 +0000</pubDate>
			<guid>https://www.wolfssl.com/forums/post8947.html#p8947</guid>
		</item>
	</channel>
</rss>
