Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wolfSSL — Vulnerabilities & Security Advisories 93

All 93 CVE vulnerabilities found in wolfSSL, with AI-generated Chinese analysis, references, and POCs.

This page serves as the vulnerability aggregation resource for the wolfSSL library, focusing on a wide range of Common Weakness Enumerations (CWE) associated with this embedded TLS/SSL implementation. It collects and organizes security issues affecting wolfSSL, spanning from its initial public releases through to the most recently disclosed patches, ensuring a comprehensive historical view of its security posture. Users can track vendor advisories to stay informed about new fixes, understand the characteristics and impact of specific weakness classes within the context of lightweight cryptographic libraries, and look up a product's vulnerability history to assess past risks and remediation efforts. This aggregation aims to provide developers, security analysts, and system integrators with a clear, consolidated view of known issues in wolfSSL, facilitating better risk management and informed decision-making during product integration or update cycles. By centralizing this information, the page supports transparency and helps stakeholders evaluate the stability and security maturity of wolfSSL over time.

Vendor: wolfSSL

CVE ID Title CVSS Severity Published
CVE-2026-6291 Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption CWE-208 - - 2026-06-25
CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData CWE-125 - - 2026-06-25
CVE-2026-5477 Prefix-substitution forgery via integer overflow in wolfCrypt CMAC CWE-190 7.5 - 2026-04-10
CVE-2026-5188 Integer underflow in X.509 SAN parsing in wolfSSL CWE-191 6.5 - 2026-04-10
CVE-2026-5500 Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass CWE-20 3.7 - 2026-04-10
CVE-2026-5501 Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates CWE-295 5.9 - 2026-04-10
CVE-2026-5466 wc_VerifyEccsiHash missing sanity check CWE-347 9.1 - 2026-04-10
CVE-2026-5479 wolfSSL EVP ChaCha20-Poly1305 AEAD authentication tag CWE-354 7.5 - 2026-04-10
CVE-2026-5460 Heap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3 CWE-416 9.1 - 2026-04-09
CVE-2026-5448 1-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBefore CWE-122 8.1 - 2026-04-09
CVE-2026-5392 wolfSSL heap OOB read in PKCS7 SignedData streaming CWE-125 9.1 - 2026-04-09
CVE-2026-5393 OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS CWE-125 9.1 - 2026-04-09
CVE-2026-5295 Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID CWE-121 9.8AI Critical AI 2026-04-09
CVE-2026-5503 out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName CWE-787 9.1AI Critical AI 2026-04-09
CVE-2026-5504 PKCS7 CBC Padding Oracle — Plaintext Recovery CWE-354 7.5AI High AI 2026-04-09
CVE-2026-5507 Session Cache Restore — Arbitrary Free via Deserialized Pointer CWE-502 8.1AI High AI 2026-04-09
CVE-2026-5772 MatchDomainName 1-Byte Stack Buffer Over-Read in Hostname Validation CWE-126 7.5AI High AI 2026-04-09
CVE-2026-5778 Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path. CWE-191 7.5AI High AI 2026-04-09
CVE-2026-5264 DTLS 1.3 ACK heap buffer overflow CWE-122 9.8AI Critical AI 2026-04-09
CVE-2026-5263 URI nameConstraints not enforced in ConfirmNameConstraints() CWE-295 7.5AI High AI 2026-04-09
CVE-2026-5446 wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse CWE-323 9.1AI Critical AI 2026-04-09
CVE-2026-5447 Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier CWE-122 9.8AI Critical AI 2026-04-09
CVE-2026-5187 Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL CWE-122 8.4AI High AI 2026-04-09
CVE-2026-5194 wolfSSL ECDSA Certificate Verification CWE-295 5.3AI Medium AI 2026-04-09
CVE-2026-4159 wc_PKCS7_DecodeEnvelopedData 1 byte out-of-bounds read CWE-125 9.1 - 2026-03-19
CVE-2026-3229 Integer Overflow in Certificate Chain Allocation CWE-122 9.8 - 2026-03-19
CVE-2026-3230 Improper key_share validation in TLS 1.3 HelloRetryRequest CWE-20 7.5 - 2026-03-19
CVE-2026-4395 Heap-based buffer overflow in wc_ecc_import_x963_ex KCAPI path CWE-122 9.1 - 2026-03-19
CVE-2026-3849 Buffer Overflow in HPKE via Oversized ECH Config CWE-787 9.8 - 2026-03-19
CVE-2026-3547 wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation CWE-125 7.5 High 2026-03-19

All 93 known CVE vulnerabilities affecting wolfSSL with full Chinese analysis, references, and POCs where available.