CVE-2026-84897

Source
https://cve.org/CVERecord?id=CVE-2026-84897
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84897.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84897
Published
2026-10-07T02:42:28Z
Modified
2026-10-09T07:06:05Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y CVSS Calculator
Summary
wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion
Details

src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) when a server receives them from an unauthenticated client. IsMessageAllowedServer() applies no direction check to the key exchange message range: when the peer is keying and no particular message is expected, which is the state a server is in for the whole window after it processes the client's KEXINIT because nothing sets handshake->expectMsgId there, the function falls out of its expectation branch without a verdict and reaches a numeric bound that admits every message id from 30 through 34. A client that negotiates diffie-hellman-group-exchange-sha256 and then sends message 31 makes the server run the client-side handler DoKexDhGexGroup(), which validates the attacker-supplied group with two 8-round Miller-Rabin primality tests, one on p and one on (p-1)/2, on a value of up to 8192 bits. The handler then returns success: the server stores the attacker's prime and generator, generates a Diffie-Hellman key pair in the attacker's group, and sends the client-role message SSH_MSG_KEX_DH_GEX_INIT (32) back to the attacker. Published RFC 3526 safe primes are the worst-case input and cost the attacker nothing to obtain. The primality validation was added in 1.5.0; versions from 1.2.0 through 1.4.22 admit the same message and enter the same client-role path without the primality cost. Message 33 is admitted as well, but on a server it is rejected before any cryptography because no public key check callback is registered, so it carries no comparable cost. Builds that define WOLFSSH_NO_DH_GEX_SHA256, which is implied by WOLFSSH_NO_DH or NO_SHA256, are unaffected.

Database specific
{
    "cna_assigner": "wolfSSL",
    "cwe_ids": [
        "CWE-372",
        "CWE-400",
        "CWE-405"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84897.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.2.0"
                },
                {
                    "fixed": "1.6.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "30"
                },
                {
                    "fixed": "34"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/wolfssl/wolfssh

Affected ranges

Type
GIT
Repo
https://github.com/wolfssl/wolfssh
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.5.0"
        },
        {
            "introduced": "1.2.0"
        },
        {
            "fixed": "1.4.22"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.2.0-stable
v1.2.2
v1.3.0-stable
v1.4.0-stable
v1.4.10-stable
v1.4.11-stable
v1.4.12-stable
v1.4.13-stable
v1.4.14-stable
v1.4.15-stable
v1.4.16
v1.4.17-stable
v1.4.18-stable
v1.4.19-stable
v1.4.2-stable
v1.4.20-stable
v1.4.21-stable
v1.4.3-stable
v1.4.4-stable
v1.4.5-stable
v1.4.6-stable
v1.4.7-stable
v1.4.8-stable
v1.4.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84897.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "332597429388241481065802417261341409358",
            "length": 2367
        },
        "id": "CVE-2026-84897-00ddc3b5",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/a472f1ee2b653f623d85ef2297321733f1dbfd22",
        "target": {
            "file": "src/internal.c",
            "function": "IsMessageAllowedServer"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "128697116366816681178397962724568946588",
            "length": 5650
        },
        "id": "CVE-2026-84897-474b24ff",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/a472f1ee2b653f623d85ef2297321733f1dbfd22",
        "target": {
            "file": "tests/regress.c",
            "function": "main"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "118513238373630913010649926792335052979",
                "249562867172711739799557390989647643018",
                "325921520442702441106489839726675749863",
                "76289822188778458399863853977056367152",
                "52564300302719386044077990138923678774",
                "321929433519072388629500615019388727461",
                "94056652126704302590815800423611593456"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-84897-63bf690c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/a472f1ee2b653f623d85ef2297321733f1dbfd22",
        "target": {
            "file": "tests/regress.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "185246754689052513008561199853287132380",
                "137609406753648681267639826552501788982",
                "149705089427072683951731583736537310304",
                "150271123820429758589687398548444471965"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-84897-ea0e1f8e",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/a472f1ee2b653f623d85ef2297321733f1dbfd22",
        "target": {
            "file": "src/internal.c"
        }
    }
]
vanir_signatures_modified
"2026-10-09T07:06:05Z"