CVE-2026-0819
- EPSS 0.1%
- Veröffentlicht 19.03.2026 16:54:33
- Zuletzt bearbeitet 29.04.2026 18:50:05
A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSignedAttributes(), when adding custom signed attributes, the code passes an incorrect capacity value (esd->signedAttribsCount) to Enc...
- EPSS 0.14%
- Veröffentlicht 11.12.2025 17:09:59
- Zuletzt bearbeitet 15.04.2026 00:35:42
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through ...
CVE-2025-11932
- EPSS 0.26%
- Veröffentlicht 21.11.2025 23:15:44
- Zuletzt bearbeitet 04.12.2025 16:09:31
The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder
CVE-2025-12889
- EPSS 0.13%
- Veröffentlicht 21.11.2025 23:06:59
- Zuletzt bearbeitet 04.12.2025 15:43:04
With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.
CVE-2025-11931
- EPSS 0.32%
- Veröffentlicht 21.11.2025 22:57:32
- Zuletzt bearbeitet 04.12.2025 16:21:09
Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used with TLS connections, only from direct calls from an applicatio...
CVE-2025-12888
- EPSS 0.29%
- Veröffentlicht 21.11.2025 22:50:30
- Zuletzt bearbeitet 04.12.2025 16:07:14
Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommend...
CVE-2025-11936
- EPSS 0.43%
- Veröffentlicht 21.11.2025 22:24:27
- Zuletzt bearbeitet 03.12.2025 18:47:25
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry v...
CVE-2025-11933
- EPSS 0.42%
- Veröffentlicht 21.11.2025 22:19:08
- Zuletzt bearbeitet 08.10.2026 10:10:00
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS e...
CVE-2025-11935
- EPSS 0.21%
- Veröffentlicht 21.11.2025 22:16:18
- Zuletzt bearbeitet 03.12.2025 18:47:32
With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHel...
CVE-2025-11934
- EPSS 0.15%
- Veröffentlicht 21.11.2025 22:12:37
- Zuletzt bearbeitet 03.12.2025 18:47:17
Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm used. For example when a client sends ECDSA P521 as the suppo...