Skip to content
cve — cve-2026-16516

grep -rl "CVE-2026-16516" ./articles

CVE-2026-16516

wolfSSH never verified that the elliptic curve in a server's host key matched the algorithm both sides had just negotiated. A machine-in-the-middle could swap in a key on a different curve, sign with its own private key, and be accepted with no error. Fixed in 1.6.0 — and it needs one more condition that is common in embedded code.

1 article — 2026-10-08

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

The host key check ran, and passed, on a curve the attacker chose for it

2026-10-08Security

wolfSSH never verified that the elliptic curve in a server's host key matched the algorithm both sides had just negotiated. A machine-in-the-middle could swap in a key on a different curve, sign with its own private key, and be accepted with no error. Fixed in 1.6.0 — and it needs one more condition that is common in embedded code.

../cve — every identifier we have covered