Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/wolfSSH

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-84897 is a medium severity vulnerability in wolfSSL wolfSSH versions 1.2.0 through before 1.6.0. It involves improper handling of Diffie-Hellman group exchange messages on the server side, allowing unauthenticated clients to send certain key exchange messages that the server incorrectly accepts. This leads the server to perform expensive primality tests and generate key pairs based on attacker-supplied parameters. Builds that disable DH GEX SHA256 are not affected.

Join the discussion

CVE-2026-83742 is an integer underflow vulnerability in wolfSSL wolfSSH versions 1.4.11 through before 1.6.0 on non-Windows platforms. It occurs in the wstrncat() function in src/port.c, where an authenticated remote attacker can cause a single null byte to be written just past the end of a stack buffer by sending a specially crafted SFTP path. This can corrupt adjacent stack memory and potentially crash the process. The vulnerability arises from incorrect size calculations leading to an unbounded string concatenation. The overflow is limited to one null byte, and no known exploits are reported in the wild.

Join the discussion

CVE-2026-83540 is a high-severity improper authentication vulnerability in the Windows port of wolfSSHd, part of wolfSSL's wolfSSH product. The flaw causes the Windows logon token from one authenticated connection to not be released before a new token is acquired for a subsequent connection. This leads to user login poisoning between connections, allowing a less privileged user with a valid account to escalate privileges by forcing a login as a more privileged user. The vulnerability affects wolfSSH versions from 1.4.15 up to but not including 1.6.0. Non-Windows builds are not impacted.

Join the discussion

CVE-2026-81535 is a missing authorization vulnerability in wolfSSH versions 1.4.8 up to but not including 1.6.0. The issue occurs when wolfSSH is built with the --enable-fwd option. The function DoChannelOpen() only enforces authorization checks on direct-tcpip channel opens, but forwarded-tcpip channel opens bypass these checks and are not limited in number. This allows a malicious SSH peer to cause unbounded memory allocation on the endpoint. Additionally, the client does not verify forwarded-tcpip opens against registered tcpip-forward requests as required by RFC 4254 section 7.2, enabling a malicious server to open forwarding channels for unauthorized addresses and ports.

Join the discussion

wolfSSH contains a vulnerability where it does not verify that the ECDSA curve identifier in a host key blob matches the algorithm negotiated during key exchange. This allows an active man-in-the-middle attacker to substitute a host key blob with a different ECDSA curve, causing the client to import the key on the wrong curve and accept a malicious key. Exploitation requires an active MitM position and a lax public key check callback. The vulnerability affects wolfSSH versions prior to 1.6.0.

Join the discussion

CVE-2026-0930 is a low-severity buffer over-read vulnerability in wolfSSL's wolfSSH version 1.4.15 on Windows. It occurs when an authenticated user sends a terminal resize request, potentially causing the server to read out of bounds on the stack and leak adjacent memory to the pseudo-console output. This vulnerability requires low privileges and no user interaction beyond authentication. There is no confirmed patch or official remediation available at this time.

Join the discussion

A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1 byte.

Join the discussion

wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.4.21 and earlier. Users of wolfSSH must update or apply the fix patch and it’s recommended to update credentials used. This fix is also recommended for wolfSSH server applications. While there aren’t any specific attacks on server applications, the same defect is present. Thanks to Aina Toky Rasoamanana of Valeo and Olivier Levillain of Telecom SudParis for the report.

Join the discussion

Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/wolfSSH
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses