CVE-2026-84897
Received Received - Intake

wolfSSH Improper Message Validation in Key Exchange

Vulnerability report for CVE-2026-84897, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: wolfSSL Inc.

Description

src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) when a server receives them from an unauthenticated client. IsMessageAllowedServer() applies no direction check to the key exchange message range: when the peer is keying and no particular message is expected, which is the state a server is in for the whole window after it processes the client's KEXINIT because nothing sets handshake->expectMsgId there, the function falls out of its expectation branch without a verdict and reaches a numeric bound that admits every message id from 30 through 34. A client that negotiates diffie-hellman-group-exchange-sha256 and then sends message 31 makes the server run the client-side handler DoKexDhGexGroup(), which validates the attacker-supplied group with two 8-round Miller-Rabin primality tests, one on p and one on (p-1)/2, on a value of up to 8192 bits. The handler then returns success: the server stores the attacker's prime and generator, generates a Diffie-Hellman key pair in the attacker's group, and sends the client-role message SSH_MSG_KEX_DH_GEX_INIT (32) back to the attacker. Published RFC 3526 safe primes are the worst-case input and cost the attacker nothing to obtain. The primality validation was added in 1.5.0; versions from 1.2.0 through 1.4.22 admit the same message and enter the same client-role path without the primality cost. Message 33 is admitted as well, but on a server it is rejected before any cryptography because no public key check callback is registered, so it carries no comparable cost. Builds that define WOLFSSH_NO_DH_GEX_SHA256, which is implied by WOLFSSH_NO_DH or NO_SHA256, are unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wolfSSL Inc. wolfSSH 1.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-405 The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."
CWE-372 The product does not properly determine which state it is in, causing it to assume it is in state X when in fact it is in state Y, causing it to perform incorrect operations in a security-relevant manner.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in wolfSSH through 1.5.0 allows an unauthenticated client to send server-to-client Diffie-Hellman group exchange messages (SSH_MSG_KEX_DH_GEX_GROUP and SSH_MSG_KEX_DH_GEX_REPLY) to the server. The server incorrectly processes these messages, leading to expensive cryptographic operations like Miller-Rabin primality tests on attacker-controlled prime numbers up to 8192 bits. This can cause denial-of-service conditions due to excessive computational load.

Detection Guidance

To detect this vulnerability, monitor for unexpected SSH_MSG_KEX_DH_GEX_GROUP (31) or SSH_MSG_KEX_DH_GEX_REPLY (33) messages sent from clients to servers in your SSH traffic. Check wolfSSH logs for unusual key exchange attempts or failed primality tests. Use packet capture tools like tcpdump or Wireshark to inspect SSH protocol messages for message IDs 31 and 33 originating from clients.

Impact Analysis

An attacker could exploit this to force a wolfSSH server to perform heavy cryptographic calculations, potentially causing the server to slow down or crash. This could disrupt SSH services, leading to downtime or degraded performance for legitimate users.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks through resource exhaustion. Attackers could force servers to perform computationally expensive primality tests on attacker-controlled inputs, potentially degrading system performance and availability. This may violate requirements for secure processing of personal or health data under GDPR Article 32 and HIPAA Security Rule integrity standards.

Mitigation Strategies

Update wolfSSH to the latest patched version that includes the fix for CVE-2026-84897. If updating is not immediately possible, disable Diffie-Hellman group exchange by setting WOLFSSH_NO_DH_GEX_SHA256 or WOLFSSH_NO_DH during compilation. Restrict SSH access to trusted networks and monitor for suspicious key exchange attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84897. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart