Browse all 12 CVE security advisories affecting wolfSSL Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.
wolfSSL provides embedded SSL/TLS libraries for IoT devices and resource-constrained systems. Historically, vulnerabilities have included buffer overflows, use-after-free errors, and improper input validation, which could lead to remote code execution or denial of service. The company maintains a moderate CVE count of five, with no major public security incidents reported. wolfSSL emphasizes FIPS 140-2 validation and supports legacy protocols for compatibility, though this may introduce potential attack surfaces. Regular security updates and a focus on memory safety in their C codebase help mitigate risks, though the complexity of cryptographic implementations remains a challenge for embedded security.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-84897 | wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion — wolfSSH CWE-372 | 6.9 | Medium | 2026-10-07 |
| CVE-2026-83742 | wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms — wolfSSH CWE-191 | 5.3 | Medium | 2026-10-07 |
| CVE-2026-81535 | wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check — wolfSSH CWE-862 | 6.3 | Medium | 2026-10-07 |
| CVE-2026-16516 | wolfSSH ECDSA host key curve not validated against negotiated algorithm — wolfSSH CWE-345 | 9.0 | Critical | 2026-10-07 |
| CVE-2024-2873 | User authentication bypass in wolfSSH server — wolfSSH CWE-287 | 9.1 | Critical | 2024-03-25 |
This page lists every published CVE security advisory associated with wolfSSL Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.