Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wolfSSL — Vulnerabilities & Security Advisories 94

Browse all 94 CVE security advisories affecting wolfSSL. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wolfSSL is an embedded SSL/TLS library primarily designed for resource-constrained environments, including IoT devices, automotive systems, and embedded Linux. Its compact footprint makes it a standard choice for secure communications in hardware with limited memory and processing power. Historically, the codebase has been associated with numerous Common Vulnerabilities and Exposures, totaling 62 recorded instances. These flaws predominantly involve memory corruption issues, such as buffer overflows and use-after-free errors, which can lead to remote code execution or denial of service. While cross-site scripting is less relevant to its backend nature, improper input validation remains a recurring theme. Notable incidents often stem from complex cryptographic implementations or parsing errors in certificate handling. The project maintains an active security response process, addressing these vulnerabilities through regular updates, though the high volume of past CVEs highlights the challenges of maintaining rigorous security standards in a widely deployed, low-level cryptographic component.

CVE ID Title CVSS Severity Published
CVE-2026-6291 Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption — wolfSSL CWE-208 - - 2026-06-25
CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData — wolfSSL CWE-125 - - 2026-06-25
CVE-2026-0930 Potential wolfSSHd Buffer out-of-bounds Read on Windows Handling Terminal Resize — wolfSSH CWE-126 8.1AI High AI 2026-04-20
CVE-2026-5477 Prefix-substitution forgery via integer overflow in wolfCrypt CMAC — wolfSSL CWE-190 7.5 - 2026-04-10
CVE-2026-5188 Integer underflow in X.509 SAN parsing in wolfSSL — wolfSSL CWE-191 6.5 - 2026-04-10
CVE-2026-5500 Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass — wolfSSL CWE-20 3.7 - 2026-04-10
CVE-2026-5501 Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates — wolfSSL CWE-295 5.9 - 2026-04-10
CVE-2026-5466 wc_VerifyEccsiHash missing sanity check — wolfSSL CWE-347 9.1 - 2026-04-10
CVE-2026-5479 wolfSSL EVP ChaCha20-Poly1305 AEAD authentication tag — wolfSSL CWE-354 7.5 - 2026-04-10
CVE-2026-5460 Heap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3 — wolfSSL CWE-416 9.1 - 2026-04-09
CVE-2026-5448 1-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBefore — wolfSSL CWE-122 8.1 - 2026-04-09
CVE-2026-5392 wolfSSL heap OOB read in PKCS7 SignedData streaming — wolfSSL CWE-125 9.1 - 2026-04-09
CVE-2026-5393 OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS — wolfSSL CWE-125 9.1 - 2026-04-09
CVE-2026-5295 Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID — wolfSSL CWE-121 9.8AI Critical AI 2026-04-09
CVE-2026-5503 out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName — wolfSSL CWE-787 9.1AI Critical AI 2026-04-09
CVE-2026-5504 PKCS7 CBC Padding Oracle — Plaintext Recovery — wolfSSL CWE-354 7.5AI High AI 2026-04-09
CVE-2026-5507 Session Cache Restore — Arbitrary Free via Deserialized Pointer — wolfSSL CWE-502 8.1AI High AI 2026-04-09
CVE-2026-5772 MatchDomainName 1-Byte Stack Buffer Over-Read in Hostname Validation — wolfSSL CWE-126 7.5AI High AI 2026-04-09
CVE-2026-5778 Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path. — wolfSSL CWE-191 7.5AI High AI 2026-04-09
CVE-2026-5264 DTLS 1.3 ACK heap buffer overflow — wolfSSL CWE-122 9.8AI Critical AI 2026-04-09
CVE-2026-5263 URI nameConstraints not enforced in ConfirmNameConstraints() — wolfSSL CWE-295 7.5AI High AI 2026-04-09
CVE-2026-5446 wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse — wolfSSL CWE-323 9.1AI Critical AI 2026-04-09
CVE-2026-5447 Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier — wolfSSL CWE-122 9.8AI Critical AI 2026-04-09
CVE-2026-5187 Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL — wolfSSL CWE-122 8.4AI High AI 2026-04-09
CVE-2026-5194 wolfSSL ECDSA Certificate Verification — wolfSSL CWE-295 5.3AI Medium AI 2026-04-09
CVE-2026-4159 wc_PKCS7_DecodeEnvelopedData 1 byte out-of-bounds read — wolfSSL CWE-125 9.1 - 2026-03-19
CVE-2026-3230 Improper key_share validation in TLS 1.3 HelloRetryRequest — wolfSSL CWE-20 7.5 - 2026-03-19
CVE-2026-4395 Heap-based buffer overflow in wc_ecc_import_x963_ex KCAPI path — wolfssl CWE-122 9.1 - 2026-03-19
CVE-2026-3547 wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation — wolfSSL CWE-125 7.5 High 2026-03-19
CVE-2026-3580 Compiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V — wolfSSL CWE-203 5.5 - 2026-03-19

This page lists every published CVE security advisory associated with wolfSSL. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.