Skip to content
THREATWIRE

CVE

MediumNo PoC

CVE-2026-84897

wolfSSH server accepts server-only DH group exchange messages from clients

wolfSSH CVE-2026-84897 lets an unauthenticated client send DH group exchange messages that only a server should send, forcing pre-authentication primality tests (CPU exhaustion) and key exchange role confusion. wolfSSL rates it Medium, CVSS 4.0 6.9. Fixed in wolfSSH 1.6.0. Not in CISA KEV. No public PoC.

CVSS
6.9
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y
Class
DoS
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
wolfSSL
Products
wolfSSH
Affected
wolfSSH 1.2.0 through 1.5.0. The primality-test CPU cost applies from 1.5.0. Builds with WOLFSSH_NO_DH_GEX_SHA256 (implied by WOLFSSH_NO_DH or NO_SHA256) are unaffected.
Fixed
wolfSSH 1.6.0 or later.
Published
7 Oct 2026
Updated
8 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-84897 is a vulnerability in wolfSSH, wolfSSL's embedded SSH library, fixed in wolfSSH 1.6.0. wolfSSL published the 1.6.0 release on GitHub on 6 October 2026, and the CVE record was published on 7 October 2026. It lets an unauthenticated client send DH group exchange messages that only a server should send, forcing pre-authentication primality tests (CPU exhaustion) and key exchange role confusion.

wolfSSL's advisory says a wolfSSH server accepted the Diffie-Hellman group exchange messages that only a server sends, SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33), from an unauthenticated client. A client that negotiated diffie-hellman-group-exchange-sha256 and sent message 31 made the server run its client-side handler. That handler primality-tests an attacker-chosen group of up to 8192 bits. wolfSSL estimates about half a second of CPU per 1 KB packet for a 4096-bit prime. The server then continues the key exchange in the client role.

No authentication is required. The CPU cost applies from 1.5.0, where the primality validation was added. Versions 1.2.0 through 1.4.22 accept the same message and enter the same client-role path, without that cost. The CVE record says message 33 is also accepted but is rejected on a server before any cryptography.

wolfSSL rates the issue Medium. wolfSSL, acting as CNA, scores it CVSS 4.0 6.9 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y; NVD shows that score from wolfSSL and has not added its own analysis yet. CWE in the CNA record: CWE-372, CWE-405, CWE-400. Affected versions: wolfSSH 1.2.0 through 1.5.0. The primality-test CPU cost applies from 1.5.0. Builds with WOLFSSH_NO_DH_GEX_SHA256 (implied by WOLFSSH_NO_DH or NO_SHA256) are unaffected. The fix landed in PR #1221 and ships in 1.6.0. wolfSSL credits Abdullah Al Ishtiaq, Kai Tu, Matthew Carter, Xiaotian Zhou, Ananna Rahman, Yilu Dong, Tianwei Yu, Ali Ranjbar and Syed Rafiul Hussain.

The CVE is not in the CISA KEV catalog. CISA-ADP SSVC records exploitation as none (automatable: yes). ThreatWire found no public proof-of-concept repository, and wolfSSL does not report exploitation. GitHub advisory GHSA-39q2-5h5r-39p7 is unreviewed.

This is one of five wolfSSH CVEs fixed in 1.6.0: CVE-2026-16516 (Critical), CVE-2026-83540 (High), and CVE-2026-84897, CVE-2026-81535 and CVE-2026-83742 (Medium).

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-84897