CVE-2026-0930: Wolfssh

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacent stack memory to the pseudo-console output.

Affected products

  • Wolfssh Wolfssh: from 1.4.15, before 1.5.0 (fixed in 1.5.0)

Published 2026-04-20. Last modified 2026-06-17.