{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-84897","assignerOrgId":"50d2cd11-d01a-48ed-9441-5bfce9d63b27","state":"PUBLISHED","assignerShortName":"wolfSSL","dateReserved":"2026-09-02T15:07:44.223Z","datePublished":"2026-10-07T02:42:28.388Z","dateUpdated":"2026-10-07T18:37:00.316Z"},"containers":{"cna":{"providerMetadata":{"orgId":"50d2cd11-d01a-48ed-9441-5bfce9d63b27","shortName":"wolfSSL","dateUpdated":"2026-10-07T02:42:28.388Z"},"title":"wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-372","description":"CWE-372 Incomplete Internal State Distinction","type":"CWE"}]},{"descriptions":[{"lang":"en","cweId":"CWE-405","description":"CWE-405 Asymmetric Resource Consumption (Amplification)","type":"CWE"}]},{"descriptions":[{"lang":"en","cweId":"CWE-400","description":"CWE-400 Uncontrolled Resource Consumption","type":"CWE"}]}],"impacts":[{"descriptions":[{"lang":"en","value":"Pre-authentication CPU exhaustion with a high work-per-byte ratio, plus key exchange role confusion. One unauthenticated packet of roughly 1 KB costs a wolfSSH server about 0.48 seconds of single-core CPU when it carries the 4096-bit RFC 3526 safe prime, and about 5.8 seconds when it carries the 8192-bit one, measured on a 64-bit desktop core; a single-threaded or embedded server is unavailable for that whole interval, and the cost repeats on every connection. The server then stores the attacker-chosen group, generates a Diffie-Hellman key pair in it, and sends the client-role message SSH_MSG_KEX_DH_GEX_INIT back to the attacker, so the key exchange continues in the wrong role until it fails. Reaching the 8192-bit case requires a wolfSSL math configuration that can represent an 8192-bit integer; a default build tops out near 4096 bits and caps the burn at roughly half a second."}]},{"capecId":"CAPEC-227","descriptions":[{"lang":"en","value":"CAPEC-227 Sustained Client Engagement"}]}],"affected":[{"vendor":"wolfSSL Inc.","product":"wolfSSH","repo":"https://github.com/wolfSSL/wolfssh","modules":["key exchange"],"programFiles":["src/internal.c"],"programRoutines":[{"name":"IsMessageAllowedServer"},{"name":"DoKexDhGexGroup"},{"name":"ValidateKexDhGexGroup"}],"versions":[{"status":"affected","version":"1.2.0","lessThanOrEqual":"1.5.0","changes":[{"at":"1.6.0","status":"unaffected"}],"versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) when a server receives them from an unauthenticated client. IsMessageAllowedServer() applies no direction check to the key exchange message range: when the peer is keying and no particular message is expected, which is the state a server is in for the whole window after it processes the client's KEXINIT because nothing sets handshake->expectMsgId there, the function falls out of its expectation branch without a verdict and reaches a numeric bound that admits every message id from 30 through 34. A client that negotiates diffie-hellman-group-exchange-sha256 and then sends message 31 makes the server run the client-side handler DoKexDhGexGroup(), which validates the attacker-supplied group with two 8-round Miller-Rabin primality tests, one on p and one on (p-1)/2, on a value of up to 8192 bits. The handler then returns success: the server stores the attacker's prime and generator, generates a Diffie-Hellman key pair in the attacker's group, and sends the client-role message SSH_MSG_KEX_DH_GEX_INIT (32) back to the attacker. Published RFC 3526 safe primes are the worst-case input and cost the attacker nothing to obtain. The primality validation was added in 1.5.0; versions from 1.2.0 through 1.4.22 admit the same message and enter the same client-role path without the primality cost. Message 33 is admitted as well, but on a server it is rejected before any cryptography because no public key check callback is registered, so it carries no comparable cost. Builds that define WOLFSSH_NO_DH_GEX_SHA256, which is implied by WOLFSSH_NO_DH or NO_SHA256, are unaffected.","supportingMedia":[{"type":"text/html","base64":false,"value":"<code>src/internal.c</code> in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages <code>SSH_MSG_KEX_DH_GEX_GROUP</code> (31) and <code>SSH_MSG_KEX_DH_GEX_REPLY</code> (33) when a server receives them from an unauthenticated client. <code>IsMessageAllowedServer()</code> applies no direction check to the key exchange message range: when the peer is keying and no particular message is expected, which is the state a server is in for the whole window after it processes the client's KEXINIT because nothing sets <code>handshake-&gt;expectMsgId</code> there, the function falls out of its expectation branch without a verdict and reaches a numeric bound that admits every message id from 30 through 34. A client that negotiates <code>diffie-hellman-group-exchange-sha256</code> and then sends message 31 makes the server run the client-side handler <code>DoKexDhGexGroup()</code>, which validates the attacker-supplied group with two 8-round Miller-Rabin primality tests, one on <code>p</code> and one on <code>(p-1)/2</code>, on a value of up to 8192 bits. The handler then returns success: the server stores the attacker's prime and generator, generates a Diffie-Hellman key pair in the attacker's group, and sends the client-role message <code>SSH_MSG_KEX_DH_GEX_INIT</code> (32) back to the attacker. Published RFC 3526 safe primes are the worst-case input and cost the attacker nothing to obtain. The primality validation was added in 1.5.0; versions from 1.2.0 through 1.4.22 admit the same message and enter the same client-role path without the primality cost. Message 33 is admitted as well, but on a server it is rejected before any cryptography because no public key check callback is registered, so it carries no comparable cost. Builds that define <code>WOLFSSH_NO_DH_GEX_SHA256</code>, which is implied by <code>WOLFSSH_NO_DH</code> or <code>NO_SHA256</code>, are unaffected.<br>"}]}],"references":[{"url":"https://github.com/wolfSSL/wolfssh/pull/1221","name":"Fix PR #1221","tags":["patch"]},{"url":"https://github.com/wolfSSL/wolfssh/commit/a472f1ee2b653f623d85ef2297321733f1dbfd22","name":"Fix commit a472f1ee (reject the KEX replies a server never receives)","tags":["patch"]},{"url":"https://www.rfc-editor.org/rfc/rfc4419.html","name":"RFC 4419 sections 3 and 5 (SSH_MSG_KEX_DH_GEX_GROUP and SSH_MSG_KEX_DH_GEX_REPLY are sent by the server)","tags":["technical-description"]},{"url":"https://www.rfc-editor.org/rfc/rfc3526.html","name":"RFC 3526 (published MODP safe primes usable as the worst-case input)","tags":["technical-description"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y"}}],"workarounds":[{"lang":"en","value":"Build wolfSSH with WOLFSSH_NO_DH_GEX_SHA256 defined so that diffie-hellman-group-exchange-sha256 is neither offered nor accepted, which removes the message 31 dispatch path entirely. Where group exchange must stay available, lowering WOLFSSH_DEFAULT_GEXDH_MAX reduces the size of the value a peer can submit for primality testing and so the cost of a single packet, but it does not stop a server from accepting the message.","supportingMedia":[{"type":"text/html","base64":false,"value":"Build wolfSSH with <code>WOLFSSH_NO_DH_GEX_SHA256</code> defined so that <code>diffie-hellman-group-exchange-sha256</code> is neither offered nor accepted, which removes the message 31 dispatch path entirely. Where group exchange must stay available, lowering <code>WOLFSSH_DEFAULT_GEXDH_MAX</code> reduces the size of the value a peer can submit for primality testing and so the cost of a single packet, but it does not stop a server from accepting the message.<br>"}]}],"credits":[{"lang":"en","value":"Abdullah Al Ishtiaq, Kai Tu, Matthew Carter, Xiaotian Zhou, Ananna Rahman, Yilu Dong, Tianwei Yu, Ali Ranjbar, Syed Rafiul Hussain","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-07T18:36:45.750446Z","id":"CVE-2026-84897","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-07T18:37:00.316Z"}}]}}