wolfSSL是wolfSSL公司开源的一个针对嵌入式系统开发人员使用的小的、可移植的嵌入式SSL编程库。 wolfSSL 3.15.0版本至5.9.1版本存在授权问题漏洞,该漏洞源于在状态恢复过程中缺少SNI/ALPN绑定,可能导致缓存的会话以不同的SNI/ALPN恢复并携带上下文未建立的客户端认证状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6679 | DTLS 1.3 ACK serialization heap buffer overflow via integer truncation | |
| CVE-2026-55958 | Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage | |
| CVE-2026-55960 | Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain valida | |
| CVE-2026-55967 | AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter | |
| CVE-2026-55961 | wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer | |
| CVE-2026-55962 | TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/ | |
| CVE-2026-55964 | Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exem | |
| CVE-2026-8720 | HMAC-BLAKE2 final discards message when key length exceeds block size | |
| CVE-2026-12340 | Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation | |
| CVE-2026-10512 | X25519 x86_64 assembly final reduction leaves non-canonical field element | |
| CVE-2026-10097 | ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static p | |
| CVE-2026-10098 | OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status | |
| CVE-2026-10592 | Wildcard DNS SAN bypasses CA name-constraint checks | |
| CVE-2026-11310 | X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchorin | |
| CVE-2026-11999 | X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert() | |
| CVE-2026-6329 | PKCS#12 MAC verification uses attacker-controlled comparison length | |
| CVE-2026-7532 | iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined | |
| CVE-2026-6094 | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData | |
| CVE-2026-6731 | X.509 name constraint bypass via Subject CN treated as a DNS name | |
| CVE-2026-6325 | Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet