wolfssh has 2 CVEs on record. The median CVSS is 8.9 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.9
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
2
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2025-14942Critical· 9.8wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication54CVE-2025-15382High· 8.1A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH45
wolfssh vulnerabilities
CVEs affecting wolfssh, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2025-15382High· 8.1A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH
A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1…
▾ Twilightwolfssh · wolfsshEPSS 0.34%via NVD
CVE-2025-14942Critical· 9.8wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication
wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with …
▾ Midnightwolfssh · wolfsshEPSS 0.40%via NVD