wolfSSL wolfEngine是wolfSSL公司的一款具备加密运算功能的引擎软件。 wolfSSL wolfEngine 1.4.1之前版本存在加密问题漏洞,该漏洞源于TLS 1.2和DTLS 1.2记录中的显式AES-CCM nonce取自记录输入缓冲区,而非附加认证数据中的TLS序列号,导致同一连接内所有AES-CCM记录使用相同的密钥和nonce对,可能造成信息泄露和认证标签伪造。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wolfSSL Inc. | wolfEngine | ≤ 1.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wolfSSL Inc. | wolfEngine | 0 ~ 1.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81019 | 7.4 HIGH | wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record |
| CVE-2026-81020 | 7.4 HIGH | wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record |
No comments yet