Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wolfSSL — Vulnerabilities & Security Advisories 93

All 93 CVE vulnerabilities found in wolfSSL, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known Common Weakness Enumeration weaknesses associated with the wolfSSL product developed by wolfSSL Inc. It serves as a centralized resource for tracking security flaws specifically affecting this lightweight SSL/TLS library implementation. The content covers a comprehensive collection of vulnerabilities ranging from critical remote code execution risks to lower-severity information disclosure issues. These entries span multiple years, capturing both historical patches and more recent security advisories as they have been reported and resolved. The time range extends from early initial releases up to the most current updates, ensuring that users can review the full lifecycle of security issues pertinent to wolfSSL versions in use. Visitors to this page can effectively track vendor-specific advisories to stay informed about timely security updates and patches. You can also gain a deeper understanding of common weakness classes by observing how they manifest within the context of embedded or constrained environments where wolfSSL is typically deployed. Additionally, the page allows you to look up a specific product version’s vulnerability history, providing context on when certain issues were addressed and which versions were impacted. This structured overview supports security teams and developers in assessing risk, prioritizing updates, and maintaining the integrity of their TLS implementations. By consolidating this information, the page facilitates proactive security management and helps users make informed decisions regarding version upgrades and mitigation strategies for known weaknesses.

Vendor: wolfSSL

CVE IDTitleCVSSSeverityPublished
CVE-2026-7511 PKCS7_verify signer confusion allows forged signatures to be accepted CWE-347--2026-06-25
CVE-2026-7532 iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined CWE-295--2026-06-25
CVE-2026-8720 HMAC-BLAKE2 final discards message when key length exceeds block size CWE-354--2026-06-25
CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status CWE-295--2026-06-25
CVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption CWE-287--2026-06-25
CVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify CWE-287--2026-06-25
CVE-2026-6092 Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured CWE-757--2026-06-25
CVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list CWE-787--2026-06-25
CVE-2026-6329 PKCS#12 MAC verification uses attacker-controlled comparison length CWE-347--2026-06-25
CVE-2026-6330 ML-KEM ARM64 NEON ciphertext comparison only compares half of the input CWE-327--2026-06-25
CVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal CWE-347--2026-06-25
CVE-2026-6412 Continued acceptance of SHA-1/MD5 digests in certificate processing CWE-327--2026-06-25
CVE-2026-6450 CRL critical extension bypass in ParseCRL_Extensions CWE-295--2026-06-25
CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info CWE-191--2026-06-25
CVE-2026-6679 DTLS 1.3 ACK serialization heap buffer overflow via integer truncation CWE-787--2026-06-25
CVE-2026-6681 PKCS#7 decode ignores caller output buffer size, writing past buffer bounds CWE-787--2026-06-25
CVE-2026-6731 X.509 name constraint bypass via Subject CN treated as a DNS name CWE-295--2026-06-25
CVE-2026-7531 Use-after-free in PQC hybrid key-share handling CWE-416--2026-06-25
CVE-2026-10097 ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery CWE-697--2026-06-25
CVE-2026-10512 X25519 x86_64 assembly final reduction leaves non-canonical field element CWE-682--2026-06-25
CVE-2026-10592 Wildcard DNS SAN bypasses CA name-constraint checks CWE-295--2026-06-25
CVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring CWE-295--2026-06-25
CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation CWE-125--2026-06-25
CVE-2026-55958 Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage CWE-787--2026-06-25
CVE-2026-55960 Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation CWE-295--2026-06-25
CVE-2026-55964 Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption) CWE-295--2026-06-25
CVE-2026-11999 X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert() CWE-295--2026-06-25
CVE-2026-55967 AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse CWE-323--2026-06-25
CVE-2026-55961 wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer CWE-347--2026-06-25
CVE-2026-6091 Partial-chain verification accepts untrusted intermediate as trust anchor CWE-295--2026-06-25

All 93 known CVE vulnerabilities affecting wolfSSL with full Chinese analysis, references, and POCs where available.