Description
src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) when a server receives them from an unauthenticated client. IsMessageAllowedServer() applies no direction check to the key exchange message range: when the peer is keying and no particular message is expected, which is the state a server is in for the whole window after it processes the client's KEXINIT because nothing sets handshake->expectMsgId there, the function falls out of its expectation branch without a verdict and reaches a numeric bound that admits every message id from 30 through 34. A client that negotiates diffie-hellman-group-exchange-sha256 and then sends message 31 makes the server run the client-side handler DoKexDhGexGroup(), which validates the attacker-supplied group with two 8-round Miller-Rabin primality tests, one on p and one on (p-1)/2, on a value of up to 8192 bits. The handler then returns success: the server stores the attacker's prime and generator, generates a Diffie-Hellman key pair in the attacker's group, and sends the client-role message SSH_MSG_KEX_DH_GEX_INIT (32) back to the attacker. Published RFC 3526 safe primes are the worst-case input and cost the attacker nothing to obtain. The primality validation was added in 1.5.0; versions from 1.2.0 through 1.4.22 admit the same message and enter the same client-role path without the primality cost. Message 33 is admitted as well, but on a server it is rejected before any cryptography because no public key check callback is registered, so it carries no comparable cost. Builds that define WOLFSSH_NO_DH_GEX_SHA256, which is implied by WOLFSSH_NO_DH or NO_SHA256, are unaffected.
Published: 2026-10-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via CPU exhaustion during pre‑authentication and key‑exchange role confusion
Action: Apply Workaround
AI Analysis

Impact

wolfSSH allows unauthenticated clients to send Diffie‑Hellman group‑exchange messages 31 and 33. The server incorrectly accepts these messages while in the pre‑authentication state, which triggers two 8‑round Miller‑Rabin primality tests on a prime of up to 8192 bits. These tests consume significant CPU time, potentially exhausting server resources before authentication occurs. The server then assumes a client‑role and responds, which can cause key‑exchange confusion but does not weaken cryptographic security. The vulnerability stems from improper input validation (CWE‑400), leading to resource exhaustion (CWE‑372) and role confusion (CWE‑405). The result is a moderate‑severity denial‑of‑service that can disrupt service availability.

Affected Systems

wolfSSL Inc. wolfSSH versions up to and including 1.5.0 are affected. All builds that permit the server to process SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) from an unauthenticated peer are vulnerable. Versions from 1.2.0 through 1.4.22 admit the same message and enter the same client‑role path without the primality cost.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. Exploitation is straightforward: an attacker merely connects to the server, negotiates a diffie‑hellman‑group‑exchange‑sha256 session, and sends message 31. No authentication or privileged access is required, making the vulnerability readily exploitable. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is clear, and the impact is to potentially degrade service availability before any authentication succeeds.

Generated by OpenCVE AI on October 7, 2026 at 04:57 UTC.

Remediation

Vendor Workaround

Build wolfSSH with WOLFSSH_NO_DH_GEX_SHA256 defined so that diffie-hellman-group-exchange-sha256 is neither offered nor accepted, which removes the message 31 dispatch path entirely. Where group exchange must stay available, lowering WOLFSSH_DEFAULT_GEXDH_MAX reduces the size of the value a peer can submit for primality testing and so the cost of a single packet, but it does not stop a server from accepting the message.


OpenCVE Recommended Actions

  • Build wolfSSH with the option WOLFSSH_NO_DH_GEX_SHA256 so that the server neither offers nor accepts diffie‑hellman‑group‑exchange‑sha256, thereby eliminating the resource‑exhaustion flaw (CWE‑372).
  • If group exchange must remain enabled, reduce the maximum group size by setting WOLFSSH_DEFAULT_GEXDH_MAX to a smaller value, thereby limiting the prime size and the cost of the primality tests (CWE‑400).
  • Upgrade to a newer wolfSSH release that corrects the direction‑check bug, or, if unavailable, block or limit SSH connections until a patched version is deployed; this resolves the input‑validation, resource exhaustion, and role‑confusion weaknesses (CWE‑400, CWE‑372, CWE‑405).

Generated by OpenCVE AI on October 7, 2026 at 04:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Wolfssl
Wolfssl wolfssh
Vendors & Products Wolfssl
Wolfssl wolfssh

Wed, 07 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Description src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) when a server receives them from an unauthenticated client. IsMessageAllowedServer() applies no direction check to the key exchange message range: when the peer is keying and no particular message is expected, which is the state a server is in for the whole window after it processes the client's KEXINIT because nothing sets handshake->expectMsgId there, the function falls out of its expectation branch without a verdict and reaches a numeric bound that admits every message id from 30 through 34. A client that negotiates diffie-hellman-group-exchange-sha256 and then sends message 31 makes the server run the client-side handler DoKexDhGexGroup(), which validates the attacker-supplied group with two 8-round Miller-Rabin primality tests, one on p and one on (p-1)/2, on a value of up to 8192 bits. The handler then returns success: the server stores the attacker's prime and generator, generates a Diffie-Hellman key pair in the attacker's group, and sends the client-role message SSH_MSG_KEX_DH_GEX_INIT (32) back to the attacker. Published RFC 3526 safe primes are the worst-case input and cost the attacker nothing to obtain. The primality validation was added in 1.5.0; versions from 1.2.0 through 1.4.22 admit the same message and enter the same client-role path without the primality cost. Message 33 is admitted as well, but on a server it is rejected before any cryptography because no public key check callback is registered, so it carries no comparable cost. Builds that define WOLFSSH_NO_DH_GEX_SHA256, which is implied by WOLFSSH_NO_DH or NO_SHA256, are unaffected.
Title wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion
Weaknesses CWE-372
CWE-400
CWE-405
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y'}


cve-icon MITRE

Status: PUBLISHED

Assigner: wolfSSL

Published:

Updated: 2026-10-07T02:42:28.388Z

Reserved: 2026-09-02T15:07:44.223Z

Link: CVE-2026-84897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T03:17:00.067

Modified: 2026-10-07T03:17:00.067

Link: CVE-2026-84897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:00:12Z

Weaknesses
  • CWE-372

    Incomplete Internal State Distinction

  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-405

    Asymmetric Resource Consumption (Amplification)