CVE-2025-11624: Wolfssh

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smaller than max handle size allowed.

Affected products

  • Wolfssh Wolfssh: from 1.3.0, up to and including 1.4.20

Published 2025-10-21. Last modified 2026-06-17.