Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the buffer, so the overflow is limited to that single null byte, which may corrupt an adjacent stack value and crash the process. Applications that call the public wolfSSH_RealPath() with an output buffer smaller than the input path are additionally exposed to an unbounded copy, because the word32 expression outSz - segSz in that length check also wraps.
CVE-2026-83742
This medium-severity CVE scores 5.3 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit-prediction score not yet available (the EPSS model rescores nightly; freshly-published CVEs typically appear within 48 hours). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- Lower severity and no public exploit yet
A fix is available — apply it.
- CVSS v3
- 5.3
- EG Score
- 5.3MEDIUMlow confidence
- EG Risk
- 24EG Risk 24/100CISA SSVC
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity53% × 45%Exploitation0% × 40%Automatability0% × 15%CISA SSVC: Track at every mission impact level.Action: A fix is available. Apply it within your standard update timelines. - EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- Not listed
CISA SSVCTrack at every mission impact level.
A fix is available. Apply it within your standard update timelines.
Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table
Published
October 7, 2026
Last Modified
October 7, 2026
Advisory Details (4)
Auto-updated Oct 7, 2026commit fbc7cd88a23b (wolfSSL/wolfssh)
Patch available: wolfSSL/wolfssh v1.6.0-stable (contains commit fbc7cd88a23b)
https://github.com/wolfSSL/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35commit 513e52b18927 (wolfSSL/wolfssh)
Patch available: wolfSSL/wolfssh v1.6.0-stable (contains commit 513e52b18927)
https://github.com/wolfSSL/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139decommit 822e4464560b (wolfSSL/wolfssh)
Patch available: wolfSSL/wolfssh v1.6.0-stable (contains commit 822e4464560b)
https://github.com/wolfSSL/wolfssh/commit/822e4464560b467580ea37a2fc03b0988d88b71fFix multiple reported issues
Patch available: wolfSSL/wolfssh v1.6.0-stable (PR #1084 merged 2026-07-16)
https://github.com/wolfSSL/wolfssh/pull/1084Vendor Advisories for CVE-2026-83742(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(3)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 9× in last 7d / 9× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-10-07 16:15 UTCGHSA enrichment
- 2026-10-07 12:21 UTCEG score recompute
- 2026-10-07 12:21 UTCGHSA enrichment
- 2026-10-07 11:38 UTCEG score recompute
- 2026-10-07 11:37 UTCGHSA enrichment
- 2026-10-07 03:31 UTCEG score recompute
- 2026-10-07 03:31 UTCGHSA enrichment
- 2026-10-07 03:02 UTCEG score recompute
- 2026-10-07 03:01 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Frequently asked(4)
What is CVE-2026-83742?
When was CVE-2026-83742 disclosed?
What is the CVSS score of CVE-2026-83742?
How do I remediate CVE-2026-83742?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-83742
Is Your Infrastructure Affected by CVE-2026-83742?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.