CVE-2025-11624: Wolfssh
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smaller than max handle size allowed.
Affected products
- Wolfssh Wolfssh: from 1.3.0, up to and including 1.4.20
Published 2025-10-21. Last modified 2026-06-17.