CVE-2026-16516
wolfSSH ECDSA host key curve not validated, enabling server impersonation
wolfSSH CVE-2026-16516 lets an active man-in-the-middle substitute an ECDSA host key on a different curve and pass the wolfSSH client's host key signature check, when the application uses a lax public key check callback. wolfSSL rates it Critical, CVSS 4.0 9.0. Fixed in wolfSSH 1.6.0. Not in CISA KEV. No public PoC.
- CVSS
- 9
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N
- Class
- Auth bypass
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- wolfSSL
- Products
- wolfSSH
- Affected
- wolfSSH through 1.5.0 (CNA range: all versions up to and including 1.5.0). All platforms.
- Fixed
- wolfSSH 1.6.0 or later.
- CWE
- CWE-345
- Published
- 7 Oct 2026
- Updated
- 8 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-16516 is a vulnerability in wolfSSH, wolfSSL's embedded SSH library, fixed in wolfSSH 1.6.0. wolfSSL published the 1.6.0 release on GitHub on 6 October 2026, and the CVE record was published on 7 October 2026. It lets an active man-in-the-middle substitute an ECDSA host key on a different curve and pass the wolfSSH client's host key signature check, when the application uses a lax public key check callback.
wolfSSL's advisory says wolfSSH did not check that the ECDSA curve in a server's host key blob matched the negotiated algorithm. The CVE record adds that the curve identifier string defined in RFC 5656 was skipped rather than compared. An active network man-in-the-middle can therefore substitute a host key blob on a different ECDSA curve. The client imports the key on that curve, and because the attacker holds the matching private key, signature verification passes and the attacker can impersonate the server.
Two conditions are required, per the CVE record: an active MitM position, and a lax public key check callback in the client application. The record's examples are trust on first use (TOFU), a check on the algorithm name only, or a fingerprint match computed from the parsed key. Clients that pin and compare the full expected host key are not described as affected. The issue is on the SSH client side of wolfSSH.
wolfSSL rates the issue Critical. wolfSSL, acting as CNA, scores it CVSS 4.0 9.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N; NVD shows that score from wolfSSL and has not added its own analysis yet. CWE in the CNA record: CWE-345. Affected versions: wolfSSH through 1.5.0 (CNA range: all versions up to and including 1.5.0). All platforms. The fix landed in PR #1022 (merged 16 June 2026), GitHub issue #1012 and ships in 1.6.0. wolfSSL credits zhangph (GitHub afldl).
The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none (automatable: no). ThreatWire found no public proof-of-concept repository, and wolfSSL does not report exploitation. GitHub advisory GHSA-c487-h25j-24jq is unreviewed.
This is one of five wolfSSH CVEs fixed in 1.6.0: CVE-2026-16516 (Critical), CVE-2026-83540 (High), and CVE-2026-84897, CVE-2026-81535 and CVE-2026-83742 (Medium).