Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wolfssl — Vulnerabilities & Security Advisories 94

Browse all 94 CVE security advisories affecting wolfssl. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wolfSSL is an embedded SSL/TLS library primarily designed for resource-constrained environments, including IoT devices, automotive systems, and embedded Linux. Its compact footprint makes it a standard choice for secure communications in hardware with limited memory and processing power. Historically, the codebase has been associated with numerous Common Vulnerabilities and Exposures, totaling 62 recorded instances. These flaws predominantly involve memory corruption issues, such as buffer overflows and use-after-free errors, which can lead to remote code execution or denial of service. While cross-site scripting is less relevant to its backend nature, improper input validation remains a recurring theme. Notable incidents often stem from complex cryptographic implementations or parsing errors in certificate handling. The project maintains an active security response process, addressing these vulnerabilities through regular updates, though the high volume of past CVEs highlights the challenges of maintaining rigorous security standards in a widely deployed, low-level cryptographic component.

High2026-06-27
PKCS7 Fixes by kareem-wolfssl · Pull Request #10128 · wolfSSL/wolfssl · GitHub
High2026-06-27
reject crls with unrecognized critical extensions by gasbytes · Pull Request #10239 · wolfSSL/wolfssl · GitHub
Medium2026-06-27
ML-KEM: fix AVX2 assembly by SparkiDev · Pull Request #10430 · wolfSSL/wolfssl · GitHub
High2026-06-27
X25519 x64 ASM: fix full reduction by SparkiDev · Pull Request #10536 · wolfSSL/wolfssl · GitHub
Medium2026-06-27
NameConstraints: support wildcard SAN by rizlik · Pull Request #10549 · wolfSSL/wolfssl · GitHub
High2026-06-27
Various fixes by Frauschi · Pull Request #10702 · wolfSSL/wolfssl · GitHub
High2026-06-27
Renesas TSIP: skip XMEMCPY on MEMORY_E from tsip_StoreMessage() by cconlon · Pull Request #10705 · wolfSSL/wolfssl · Git
High2026-06-27
20260616-aes-fixes by douzzer · Pull Request #10709 · wolfSSL/wolfssl · GitHub
High2026-04-10
Dtls13: ack management improvements by rizlik · Pull Request #10076 · wolfSSL/wolfssl · GitHub
High2026-04-10
Additional fixes by Frauschi · Pull Request #10116 · wolfSSL/wolfssl · GitHub
High2026-04-10
Various GI and ZD fixes by rlm2002 · Pull Request #10079 · wolfSSL/wolfssl · GitHub
High2026-04-10
Various security fixes and tests by anhu · Pull Request #10088 · wolfSSL/wolfssl · GitHub
High2026-04-10
20260403-WC_FIPS_186 by douzzer · Pull Request #10131 · wolfSSL/wolfssl · GitHub
Medium2026-04-10
Add bounds check in PKCS7 streaming indefinite-length end-of-content parsing by anhu · Pull Request #10039 · wolfSSL/wol
High2026-04-10
Various fixes by Frauschi · Pull Request #10102 · wolfSSL/wolfssl · GitHub
High2026-04-10
Add bounds check on wolfSSL_X509_notBefore and wolfSSL_X509_notAfter by padelsbach · Pull Request #10071 · wolfSSL/wolfs
Medium2025-11-22
GitHub - wolfSSL/wolfssl: The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices
HighSA-CORE-2024-05702024-08-31
Release wolfSSL Release 5.7.0 (Mar 20, 2024) · wolfSSL/wolfssl · GitHub
High2024-08-29
Release wolfSSL Release 5.7.2 (July 8, 2024) · wolfSSL/wolfssl · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with wolfssl. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.