Wolfssl

Wolfssl

155 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 08.10.2026 00:00:00
  • Zuletzt bearbeitet 08.10.2026 21:34:48

An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certificates without S...

  • EPSS 0.28%
  • Veröffentlicht 27.09.2026 09:24:31
  • Zuletzt bearbeitet 02.10.2026 18:58:59

In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a partial wolfSSL_read() which is sometimes...

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 27.09.2026 09:22:42
  • Zuletzt bearbeitet 30.09.2026 17:30:04

In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUE...

  • EPSS 0.23%
  • Veröffentlicht 27.09.2026 09:18:43
  • Zuletzt bearbeitet 02.10.2026 18:58:31

wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA and the leaf c...

  • EPSS 0.22%
  • Veröffentlicht 27.09.2026 09:16:58
  • Zuletzt bearbeitet 02.10.2026 18:57:50

A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL && !cert->isC...

  • EPSS 0.21%
  • Veröffentlicht 27.09.2026 09:14:44
  • Zuletzt bearbeitet 02.10.2026 18:57:29

A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.8.4 through...

  • EPSS 0.55%
  • Veröffentlicht 27.09.2026 09:12:39
  • Zuletzt bearbeitet 29.09.2026 17:17:12

When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication. RPK is off by default and o...

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 27.09.2026 09:07:35
  • Zuletzt bearbeitet 02.10.2026 18:57:08

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_ce...

  • EPSS 0.19%
  • Veröffentlicht 27.09.2026 09:05:37
  • Zuletzt bearbeitet 02.10.2026 18:41:59

A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server's Fin...

  • EPSS 0.23%
  • Veröffentlicht 27.09.2026 09:00:59
  • Zuletzt bearbeitet 29.09.2026 19:07:30

When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that carries no Authority Information Access OCSP URL, and accepts a certificate the loa...