{"id":"CVE-2025-15382","title":"A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH","summary":"A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-125"],"vendor":"wolfssh","product":"wolfssh","affected":["wolfssh >= 1.4.12, < 1.4.22"],"patched":["wolfssh 1.4.22"],"published":"2026-01-06","updated":"2026-09-30","sourceUpdated":"2026-09-30T22:10:00.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15382","references":[{"url":"https://github.com/wolfSSL/wolfssh/pull/859","label":"facts@wolfssl.com"}],"tags":["nvd"],"epss":0.00344,"epssPercentile":0.25435,"ingestedAt":"2026-09-30T22:27:27.709Z","slug":"CVE-2025-15382","body":"## Overview\n\nA heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1 byte.\n\n## Affected\n\n- `wolfssh >= 1.4.12, < 1.4.22`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `wolfssh 1.4.22`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}