CVE-2026-83742
wolfSSH SFTP path handling off-by-one NUL write on non-Windows
wolfSSH CVE-2026-83742 lets an authenticated SFTP user send a crafted path that writes one NUL byte past a stack buffer in wolfSSH_RealPath(), corrupting an adjacent value and crashing the process. wolfSSL rates it Medium, CVSS 4.0 5.3. Fixed in wolfSSH 1.6.0. Not in CISA KEV. No public PoC.
- CVSS
- 5.3
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N
- Class
- DoS
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- wolfSSL
- Products
- wolfSSH
- Affected
- wolfSSH 1.4.11 through 1.5.0 on non-Windows platforms.
- Fixed
- wolfSSH 1.6.0 or later.
- Published
- 7 Oct 2026
- Updated
- 8 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-83742 is a vulnerability in wolfSSH, wolfSSL's embedded SSH library, fixed in wolfSSH 1.6.0. wolfSSL published the 1.6.0 release on GitHub on 6 October 2026, and the CVE record was published on 7 October 2026. It lets an authenticated SFTP user send a crafted path that writes one NUL byte past a stack buffer in wolfSSH_RealPath(), corrupting an adjacent value and crashing the process.
wolfSSL's advisory says wolfSSH_RealPath() bounded each appended path component by the space left in the output buffer rather than by the buffer's size. Once an accumulated path passed the halfway mark, an unsigned length computation in wstrncat() wrapped and the copy became effectively unbounded. A crafted SFTP path could then write a single terminating NUL one byte past the end of a stack buffer, corrupting an adjacent value and crashing the process.
The attacker needs an authenticated session, and only non-Windows builds are affected. wolfSSL adds that an application calling the public wolfSSH_RealPath() API directly with an output buffer smaller than its input is further exposed to an unbounded copy.
wolfSSL rates the issue Medium. wolfSSL, acting as CNA, scores it CVSS 4.0 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N; NVD shows that score from wolfSSL and has not added its own analysis yet. CWE in the CNA record: CWE-191, CWE-121, CWE-193. Affected versions: wolfSSH 1.4.11 through 1.5.0 on non-Windows platforms. The fix landed in PR #1084 and ships in 1.6.0. wolfSSL credits Asif Nadaf, independent security researcher.
The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none (automatable: no). ThreatWire found no public proof-of-concept repository, and wolfSSL does not report exploitation. GitHub advisory GHSA-4ff8-whrv-3wcm is unreviewed.
This is one of five wolfSSH CVEs fixed in 1.6.0: CVE-2026-16516 (Critical), CVE-2026-83540 (High), and CVE-2026-84897, CVE-2026-81535 and CVE-2026-83742 (Medium).