CVE-2026-0930 is an out-of-bounds read vulnerability in wolfSSHd on Windows that occurs during terminal resize request handling. An authenticated user can trigger this flaw after establishing an SSH connection, resulting in the disclosure of adjacent stack memory through the pseudo-console output. The vulnerability affects wolfSSH implementations on Windows systems and requires prior authentication to exploit. The attack vector is network-based with low complexity, though the CVSS score is not currently available. Exploitation is not known to be active in the wild, with no public exploit code identified, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. Community attention remains minimal, as reflected by the low EPSS score of 0.0004 and moderate FAUCET risk score of 32.0, indicating this is a lower-priority security issue requiring standard patch management practices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.15, < 1.5.0CPE matchmatch criteria | cpe:2.3:a:wolfssh:wolfssh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.