Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wolfSSL — Vulnerabilities & Security Advisories 104

All 104 CVE vulnerabilities found in wolfSSL, with AI-generated Chinese analysis, references, and POCs.

This page aggregates recorded vulnerabilities for wolfSSL, a lightweight TLS/SSL library, organized by common weakness types and security tags. It collects known issues affecting the wolfSSL product, covering advisories published over the recent historical period up to the current date. Readers can use this view to track the vendor’s advisory releases, understand the prevalence of specific weakness classes, and review the vulnerability history of the product. The data is presented as a neutral, structured collection suitable for security research, patch management, and risk assessment. No promotional language or specific CVE identifiers are listed in this introductory text; the focus is on the aggregate view of security defects associated with the wolfSSL codebase.

Vendor: wolfSSL

CVE ID Title CVSS Severity Published
CVE-2026-5263 URI nameConstraints not enforced in ConfirmNameConstraints() CWE-295 7.5AI High AI 2026-04-09
CVE-2026-5446 wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse CWE-323 9.1AI Critical AI 2026-04-09
CVE-2026-5447 Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier CWE-122 9.8AI Critical AI 2026-04-09
CVE-2026-5187 Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL CWE-122 8.4AI High AI 2026-04-09
CVE-2026-5194 wolfSSL ECDSA Certificate Verification CWE-295 5.3AI Medium AI 2026-04-09
CVE-2026-4159 wc_PKCS7_DecodeEnvelopedData 1 byte out-of-bounds read CWE-125 9.1 - 2026-03-19
CVE-2026-3229 Integer Overflow in Certificate Chain Allocation CWE-122 9.8 - 2026-03-19
CVE-2026-3230 Improper key_share validation in TLS 1.3 HelloRetryRequest CWE-20 7.5 - 2026-03-19
CVE-2026-4395 Heap-based buffer overflow in wc_ecc_import_x963_ex KCAPI path CWE-122 9.1 - 2026-03-19
CVE-2026-3849 Buffer Overflow in HPKE via Oversized ECH Config CWE-787 9.8 - 2026-03-19
CVE-2026-3547 wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation CWE-125 7.5 High 2026-03-19
CVE-2026-3549 ECH parsing heap buffer overflow CWE-122 9.1 - 2026-03-19
CVE-2026-3580 Compiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V CWE-203 5.5 - 2026-03-19
CVE-2026-3579 Non-constant time multiplication subroutine __muldi3 on RISC-V RV32I CWE-203 7.5 - 2026-03-19
CVE-2026-3548 Buffer overflow in CRL number parsing in wolfSSL CWE-787 8.8 - 2026-03-19
CVE-2026-2646 Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function CWE-122 8.1 - 2026-03-19
CVE-2026-2645 Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2 CWE-358 7.5 - 2026-03-19
CVE-2026-1005 Integer underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt path CWE-191 7.5 - 2026-03-19
CVE-2026-0819 Stack buffer overflow in PKCS7 SignedData encoding with custom signed attributes CWE-121 9.8 - 2026-03-19
CVE-2025-13912 Potential non-constant time compiled code with Clang LLVM CWE-203 2.9AI Low AI 2025-12-11
CVE-2025-12889 TLS 1.2 Client Can Downgrade Digest Used CWE-20 7.5 - 2025-11-21
CVE-2025-11932 Timing Side-Channel in PSK Binder Verification CWE-203 5.9 - 2025-11-21
CVE-2025-11931 Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt CWE-191 9.8 - 2025-11-21
CVE-2025-12888 Constant Time Issue with Xtensa-based ESP32 and X22519 CWE-203 5.9 - 2025-11-21
CVE-2025-11936 Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello CWE-20 7.5 - 2025-11-21
CVE-2025-11933 DoS Vulnerability in wolfSSL TLS 1.3 CKS Extension CWE-20 7.5 - 2025-11-21
CVE-2025-11934 Improper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerify CWE-20 5.3 - 2025-11-21
CVE-2025-11935 Forward Secrecy Violation in WolfSSL TLS 1.3 CWE-326 8.1 - 2025-11-21
CVE-2025-7396 Curve25519 Blinding 6.8 - 2025-07-18
CVE-2025-7394 OpenSSL 安全漏洞 CWE-200 5.3 - 2025-07-18

All 104 known CVE vulnerabilities affecting wolfSSL with full Chinese analysis, references, and POCs where available.