CVE-2026-16516
Received Received - Intake

wolfSSH ECDSA Curve Mismatch in Key Exchange

Vulnerability report for CVE-2026-16516, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: wolfSSL Inc.

Description

wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via NameToId/wcPrimeForId without checking against the negotiated ssh->handshake->pubKeyId, and the RFC 5656 curve identifier string is discarded via GetSkip() rather than compared. An active network man-in-the-middle attacker can substitute a host key blob containing a different ECDSA curve, causing the client to import the key on the wrong curve. Because the attacker controls the private key for the substituted curve, signature verification passes. Exploitation requires an active MitM position and a lax public key check callback (e.g., TOFU, algorithm-name-only check, or fingerprint match against the parsed key).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wolfSSL Inc. wolfSSH 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

wolfSSH fails to validate that the ECDSA curve identifier in a host key blob matches the negotiated algorithm during SSH key exchange. An attacker in a man-in-the-middle position can substitute a different curve in the key blob, causing the client to use the wrong curve. Signature verification still passes because the attacker controls the private key for the substituted curve.

Detection Guidance

To detect this vulnerability, check if your wolfSSH version is affected by reviewing the library version and comparing it against the fixed commit 31d1369. Use commands like 'wolfssh-config --version' or inspect package metadata. Monitor SSH handshake logs for unexpected ECDSA curve mismatches or invalid curve identifiers during key exchange.

Impact Analysis

This vulnerability allows an active network attacker to downgrade the security of ECDSA host keys by forcing a weaker curve. If your application uses wolfSSH with a lax public key check (like TOFU or fingerprint matching), an attacker could impersonate a server or client by substituting a weaker curve key.

Mitigation Strategies

Immediately update wolfSSH to the latest version containing the fix in commit 31d1369. If updating is not possible, disable ECDSA host key algorithms in SSH configurations or enforce strict public key validation callbacks to reject mismatched curves. Ensure all SSH clients and servers use the patched version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16516. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart