Skip to content
THREATWIRE

CVE

MediumNo PoC

CVE-2026-83742

wolfSSH SFTP path handling off-by-one NUL write on non-Windows

wolfSSH CVE-2026-83742 lets an authenticated SFTP user send a crafted path that writes one NUL byte past a stack buffer in wolfSSH_RealPath(), corrupting an adjacent value and crashing the process. wolfSSL rates it Medium, CVSS 4.0 5.3. Fixed in wolfSSH 1.6.0. Not in CISA KEV. No public PoC.

CVSS
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N
Class
DoS
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
wolfSSL
Products
wolfSSH
Affected
wolfSSH 1.4.11 through 1.5.0 on non-Windows platforms.
Fixed
wolfSSH 1.6.0 or later.
Published
7 Oct 2026
Updated
8 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-83742 is a vulnerability in wolfSSH, wolfSSL's embedded SSH library, fixed in wolfSSH 1.6.0. wolfSSL published the 1.6.0 release on GitHub on 6 October 2026, and the CVE record was published on 7 October 2026. It lets an authenticated SFTP user send a crafted path that writes one NUL byte past a stack buffer in wolfSSH_RealPath(), corrupting an adjacent value and crashing the process.

wolfSSL's advisory says wolfSSH_RealPath() bounded each appended path component by the space left in the output buffer rather than by the buffer's size. Once an accumulated path passed the halfway mark, an unsigned length computation in wstrncat() wrapped and the copy became effectively unbounded. A crafted SFTP path could then write a single terminating NUL one byte past the end of a stack buffer, corrupting an adjacent value and crashing the process.

The attacker needs an authenticated session, and only non-Windows builds are affected. wolfSSL adds that an application calling the public wolfSSH_RealPath() API directly with an output buffer smaller than its input is further exposed to an unbounded copy.

wolfSSL rates the issue Medium. wolfSSL, acting as CNA, scores it CVSS 4.0 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N; NVD shows that score from wolfSSL and has not added its own analysis yet. CWE in the CNA record: CWE-191, CWE-121, CWE-193. Affected versions: wolfSSH 1.4.11 through 1.5.0 on non-Windows platforms. The fix landed in PR #1084 and ships in 1.6.0. wolfSSL credits Asif Nadaf, independent security researcher.

The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none (automatable: no). ThreatWire found no public proof-of-concept repository, and wolfSSL does not report exploitation. GitHub advisory GHSA-4ff8-whrv-3wcm is unreviewed.

This is one of five wolfSSH CVEs fixed in 1.6.0: CVE-2026-16516 (Critical), CVE-2026-83540 (High), and CVE-2026-84897, CVE-2026-81535 and CVE-2026-83742 (Medium).

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-83742