CVE-2026-0930
Received Received - Intake
Out-of-Bounds Read in wolfSSHd Windows Terminal Resize Leak

Publication date: 2026-04-20

Last updated on: 2026-04-24

Assigner: wolfSSL Inc.

Description
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacent stack memory to the pseudo-console output.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-20
Last Modified
2026-04-24
Generated
2026-06-16
AI Q&A
2026-04-21
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
wolfssh wolfssh From 1.4.15 (inc) to 1.5.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
CWE-126 The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

The impact of this vulnerability is that an authenticated user could access memory adjacent to the stack, potentially leaking sensitive information through the pseudo-console output. This could lead to unintended disclosure of data that resides in the adjacent stack memory.

Executive Summary

This vulnerability involves a potential out of bounds read in wolfSSHd on Windows when handling a terminal resize request. An authenticated user who has established a connection can trigger this out of bounds read, which causes adjacent stack memory to be leaked to the pseudo-console output.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0930. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart