wolfssh vulnerabilities
CVEs whose affected-version data names the wolfssh package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-15382High· 8.1A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH
A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1…
▾ Twilightwolfssh · wolfsshEPSS 0.34%via NVD
CVE-2025-14942Critical· 9.8wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication
wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with …
▾ Midnightwolfssh · wolfsshEPSS 0.40%via NVD