Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wolfSSL Inc. — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting wolfSSL Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wolfSSL provides embedded SSL/TLS libraries for IoT devices and resource-constrained systems. Historically, vulnerabilities have included buffer overflows, use-after-free errors, and improper input validation, which could lead to remote code execution or denial of service. The company maintains a moderate CVE count of five, with no major public security incidents reported. wolfSSL emphasizes FIPS 140-2 validation and supports legacy protocols for compatibility, though this may introduce potential attack surfaces. Regular security updates and a focus on memory safety in their C codebase help mitigate risks, though the complexity of cryptographic implementations remains a challenge for embedded security.

CVE ID Title CVSS Severity Published
CVE-2026-84897 wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion — wolfSSH CWE-372 6.9 Medium 2026-10-07
CVE-2026-83742 wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms — wolfSSH CWE-191 5.3 Medium 2026-10-07
CVE-2026-81535 wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check — wolfSSH CWE-862 6.3 Medium 2026-10-07
CVE-2026-16516 wolfSSH ECDSA host key curve not validated against negotiated algorithm — wolfSSH CWE-345 9.0 Critical 2026-10-07
CVE-2026-81341 wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records — wolfEngine CWE-323 6.5 Medium 2026-08-28
CVE-2026-81020 wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record — wolfEngine CWE-323 7.4 High 2026-08-28
CVE-2026-81019 wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record — wolfProvider CWE-323 7.4 High 2026-08-28
CVE-2026-3849 Buffer Overflow in HPKE via Oversized ECH Config — wolfSSL CWE-787 9.8 - 2026-03-19
CVE-2026-3503 Fault injection attack with ML-DSA and ML-KEM on ARM — wolfSSL (wolfCrypt) CWE-335 6.1 - 2026-03-19
CVE-2025-7844 wolfTPM library wrapper function `wolfTPM2_RsaKey_TpmToWolf` copies external data to a fixed-size stack buffer without length validation potentially causing stack-based buffer overflow — wolfTPM CWE-121 9.1AI Critical AI 2025-08-04
CVE-2024-5288 Safe-error attack on TLS 1.3 Protocol — wolfSSL CWE-922 5.1 Medium 2024-08-27
CVE-2024-2873 User authentication bypass in wolfSSH server — wolfSSH CWE-287 9.1 Critical 2024-03-25

This page lists every published CVE security advisory associated with wolfSSL Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.