Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wolfSSL — Vulnerabilities & Security Advisories 104

All 104 CVE vulnerabilities found in wolfSSL, with AI-generated Chinese analysis, references, and POCs.

This page aggregates recorded vulnerabilities for wolfSSL, a lightweight TLS/SSL library, organized by common weakness types and security tags. It collects known issues affecting the wolfSSL product, covering advisories published over the recent historical period up to the current date. Readers can use this view to track the vendor’s advisory releases, understand the prevalence of specific weakness classes, and review the vulnerability history of the product. The data is presented as a neutral, structured collection suitable for security research, patch management, and risk assessment. No promotional language or specific CVE identifiers are listed in this introductory text; the focus is on the aggregate view of security defects associated with the wolfSSL codebase.

Vendor: wolfSSL

CVE ID Title CVSS Severity Published
CVE-2026-15442 Heap use-after-free on read during bidirectional (D)TLS shutdown CWE-416 2.3 Low 2026-09-27
CVE-2026-89102 OCSP stapling v2 multi accepts non-CA chain certificates as issuers CWE-295 8.3 High 2026-09-27
CVE-2026-89133 NameConstraints not enforced across unconstrained intermediate CA CWE-295 6.3 Medium 2026-09-27
CVE-2026-89134 Subject CN name-constraint check bypassed when non-DNS SAN present CWE-295 6.3 Medium 2026-09-27
CVE-2026-89135 Failed X509_verify_cert leaves unverified CA in shared CertManager CWE-295 6.3 Medium 2026-09-27
CVE-2026-89136 Client accepts unsolicited RawPublicKey server certificate type CWE-287 8.3 High 2026-09-27
CVE-2026-93302 Trusted peer certificate match ignores public key, allowing forged CA clones CWE-295 8.3 High 2026-09-27
CVE-2026-93304 (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange CWE-696 6.3 Medium 2026-09-27
CVE-2026-94417 CRL check skipped when OCSP enabled and certificate has no OCSP URL CWE-299 2.3 Low 2026-09-27
CVE-2026-94418 Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY CWE-347 2.3 Low 2026-09-27
CVE-2026-94419 Client session cache reference poisoning allows resumption with wrong server CWE-287 2.3 Low 2026-09-27
CVE-2026-7511 PKCS7_verify signer confusion allows forged signatures to be accepted CWE-347 - - 2026-06-25
CVE-2026-7532 iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined CWE-295 - - 2026-06-25
CVE-2026-8720 HMAC-BLAKE2 final discards message when key length exceeds block size CWE-354 - - 2026-06-25
CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status CWE-295 - - 2026-06-25
CVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption CWE-287 - - 2026-06-25
CVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify CWE-287 - - 2026-06-25
CVE-2026-6092 Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured CWE-757 - - 2026-06-25
CVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list CWE-787 - - 2026-06-25
CVE-2026-6329 PKCS#12 MAC verification uses attacker-controlled comparison length CWE-347 - - 2026-06-25
CVE-2026-6330 ML-KEM ARM64 NEON ciphertext comparison only compares half of the input CWE-327 - - 2026-06-25
CVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal CWE-347 - - 2026-06-25
CVE-2026-6412 Continued acceptance of SHA-1/MD5 digests in certificate processing CWE-327 - - 2026-06-25
CVE-2026-6450 CRL critical extension bypass in ParseCRL_Extensions CWE-295 - - 2026-06-25
CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info CWE-191 - - 2026-06-25
CVE-2026-6679 DTLS 1.3 ACK serialization heap buffer overflow via integer truncation CWE-787 - - 2026-06-25
CVE-2026-6681 PKCS#7 decode ignores caller output buffer size, writing past buffer bounds CWE-787 - - 2026-06-25
CVE-2026-6731 X.509 name constraint bypass via Subject CN treated as a DNS name CWE-295 - - 2026-06-25
CVE-2026-7531 Use-after-free in PQC hybrid key-share handling CWE-416 - - 2026-06-25
CVE-2026-10097 ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery CWE-697 - - 2026-06-25

All 104 known CVE vulnerabilities affecting wolfSSL with full Chinese analysis, references, and POCs where available.