CVE-2026-83742

MEDIUMPre-NVD 5.35.3
EchelonGraph scoreLOW confidence

This medium-severity CVE scores 5.3 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit-prediction score not yet available (the EPSS model rescores nightly; freshly-published CVEs typically appear within 48 hours). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).

Triggered by: NVD CVSS baseline
Sources: secondary
Trending — 3 sources updated this week
5.3EG
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS PROB: —CVSS: 5.3Exploit: None knownExposed services: Not assessed

A fix is available — apply it.

Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the buffer, so the overflow is limited to that single null byte, which may corrupt an adjacent stack value and crash the process. Applications that call the public wolfSSH_RealPath() with an output buffer smaller than the input path are additionally exposed to an unbounded copy, because the word32 expression outSz - segSz in that length check also wraps.

CVSS v3
5.3
EG Score
5.3MEDIUMlow confidence
EG Risk
24
EG Risk 24/100CISA SSVC

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity53% × 45%
Exploitation0% × 40%
Automatability0% × 15%
CISA SSVC: Track at every mission impact level.
Action: A fix is available. Apply it within your standard update timelines.
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

CISA SSVCTrack at every mission impact level.

A fix is available. Apply it within your standard update timelines.

Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table

Published

October 7, 2026

Last Modified

October 7, 2026

Advisory Details (4)

Auto-updated Oct 7, 2026
Patch available. Sources: github_pr, github_commit.
github_commit Patch Available

commit fbc7cd88a23b (wolfSSL/wolfssh)

Patch available: wolfSSL/wolfssh v1.6.0-stable (contains commit fbc7cd88a23b)

https://github.com/wolfSSL/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35
github_commit Patch Available

commit 513e52b18927 (wolfSSL/wolfssh)

Patch available: wolfSSL/wolfssh v1.6.0-stable (contains commit 513e52b18927)

https://github.com/wolfSSL/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139de
github_commit Patch Available

commit 822e4464560b (wolfSSL/wolfssh)

Patch available: wolfSSL/wolfssh v1.6.0-stable (contains commit 822e4464560b)

https://github.com/wolfSSL/wolfssh/commit/822e4464560b467580ea37a2fc03b0988d88b71f
github_pr Patch Available

Fix multiple reported issues

Patch available: wolfSSL/wolfssh v1.6.0-stable (PR #1084 merged 2026-07-16)

https://github.com/wolfSSL/wolfssh/pull/1084

Vendor Advisories for CVE-2026-83742(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Weakness Classification(3)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 9× in last 7d / 9× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-10-07 16:15 UTCGHSA enrichment
  2. 2026-10-07 12:21 UTCEG score recompute
  3. 2026-10-07 12:21 UTCGHSA enrichment
  4. 2026-10-07 11:38 UTCEG score recompute
  5. 2026-10-07 11:37 UTCGHSA enrichment
  6. 2026-10-07 03:31 UTCEG score recompute
  7. 2026-10-07 03:31 UTCGHSA enrichment
  8. 2026-10-07 03:02 UTCEG score recompute
  9. 2026-10-07 03:01 UTCMITRE cvelistV5first tracked

Frequently asked(4)

What is CVE-2026-83742?
CVE-2026-83742 is a medium vulnerability published on October 7, 2026. Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSHRealPath() in src/ssh.c…
When was CVE-2026-83742 disclosed?
CVE-2026-83742 was first published on October 7, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
What is the CVSS score of CVE-2026-83742?
CVE-2026-83742 has a CVSS base score of 5.3 (a secondary CVSS source that NVD displays; NVD's own analysis pending). The EG score is currently aggregating — additional source signals are being incorporated as they become available..
How do I remediate CVE-2026-83742?
A fix for CVE-2026-83742 is available: update to the fixed version the vendor names in its advisory. The vendor advisories EchelonGraph has for CVE-2026-83742 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-83742

Explore →

Is Your Infrastructure Affected by CVE-2026-83742?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.