Skip to main content

Vendor archive

wolfssl CVEs

Beta · best-effort

149 CVEs tagged to vendor wolfssl15 Critical, 37 High, 67 Medium, 30 Low, 0 Unrated.

CVE-2025-11931

Published Nov 21, 2025

Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is n…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11935

Published Nov 21, 2025

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection usin…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-7396

Published Jul 18, 2025

In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7394

Published Jul 18, 2025

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_byt…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1543

Published Aug 29, 2024

The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment s…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5991

Published Aug 27, 2024

In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5814

Published Aug 27, 2024

A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5288

Published Aug 27, 2024

An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in sig…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1544

Published Aug 27, 2024

Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the order of the elliptic curve. Meaning k =…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0901

Published Mar 25, 2024

Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed packet with the correct length.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6936

Published Feb 20, 2024

In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6937

Published Feb 15, 2024

wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was possible to combine (D)TLS messages using different keys in…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6935

Published Feb 9, 2024

wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the following options to configur…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3724

Published Jul 17, 2023

If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-42905

Published Nov 7, 2022

In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-42961

Published Oct 15, 2022

An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39173

Published Sep 29, 2022

In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44718

Published Sep 2, 2022

wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) posi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38153

Published Aug 31, 2022

An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle attackers or a malicious serv…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38152

Published Aug 31, 2022

An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34293

Published Aug 8, 2022

wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a check for return-routability can be skipped.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25640

Published Feb 24, 2022

In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handsha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25638

Published Feb 24, 2022

In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differ…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 149 CVEsPage 4 of 6