Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93304— (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange

Quick assessment

Affected
wolfSSL wolfSSL
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述翻译如下: 在 TLS 1.2 或 DTLS 1.2 的客户端中,如果客户端在其尚未发送 ClientKeyExchange 消息之前就接受了来自服务器的 ChangeCipherSpec 消息,将会出现安全问题。此时,主密钥(master secret)尚未生成,因此客户端会使用一个已知的(确定性的)密钥派生出读取密钥,并用该密钥验证服务器的 Finished 消息。攻击者可以利用这种不按顺序收到的 ChangeCipherSpec 消息,冒充服务器完成握手过程,并发送客户端认为可信的数据。由于客户端自身

CVSS 6.3 · Medium EPSS 0.19% · P8
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93304

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
Source: CVE Program / CVE List V5
Vulnerability Description
A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server's Finished against that same key. An out-of-order ChangeCipherSpec can therefore be used by an attacker to complete the handshake in place of the server and send data the client accepts as authentic. The client's own traffic still uses correctly derived keys, so the attacker cannot read it, and the genuine server never completes the handshake. DTLS 1.2 clients are exposed because a datagram read can deliver the out-of-order records on its own. TLS 1.2 clients are exposed when the application supplies received bytes with wolfSSL_inject() or enables read ahead. For certificate suites, the attacker must be in a man-in-the-middle position. For PSK (Pre Shared Key) connections, any fake server can succeed without knowing the PSK.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不正确的行为次序
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL wolfSSL 4.7.0 ~ 5.9.2 -

II. Public POCs for CVE-2026-93304

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93304

请登录查看更多情报信息。

Other References for CVE-2026-93304 (1)

Same Patch Batch · wolfSSL · 2026-09-27 · 11 CVEs total

CVE-2026-93302 8.3 HIGH Trusted peer certificate match ignores public key, allowing forged CA clones
CVE-2026-89136 8.3 HIGH Client accepts unsolicited RawPublicKey server certificate type
CVE-2026-89102 8.3 HIGH OCSP stapling v2 multi accepts non-CA chain certificates as issuers
CVE-2026-89133 6.3 MEDIUM NameConstraints not enforced across unconstrained intermediate CA
CVE-2026-89134 6.3 MEDIUM Subject CN name-constraint check bypassed when non-DNS SAN present
CVE-2026-89135 6.3 MEDIUM Failed X509_verify_cert leaves unverified CA in shared CertManager
CVE-2026-15442 2.3 LOW Heap use-after-free on read during bidirectional (D)TLS shutdown
CVE-2026-94418 2.3 LOW Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
CVE-2026-94419 2.3 LOW Client session cache reference poisoning allows resumption with wrong server
CVE-2026-94417 2.3 LOW CRL check skipped when OCSP enabled and certificate has no OCSP URL

IV. Related Vulnerabilities

V. Comments for CVE-2026-93304

No comments yet


Leave a comment