CVE-2026-16516 - wolfSSH ECDSA host key curve not validated against negotiated algorithm
CVE ID :CVE-2026-16516 Published : Oct. 7, 2026, 2:38 a.m. | 50 minutes ago Description :wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm...