📦 Wolfssl

by Wolfssl

🔍 What is Wolfssl?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-7394

CRITICAL CVSS 9.8 Jul 18, 2025

This vulnerability in wolfSSL's OpenSSL compatibility layer causes predictable random number generation after fork() operations, potentially leading to weak cryptographic keys. It affects applications...

CVE-2023-3724

CRITICAL CVSS 9.1 Jul 17, 2023

This vulnerability in wolfSSL's TLS 1.3 implementation allows an attacker to compromise TLS session encryption when a client connects to a malicious server. Attackers can reconstruct session keys and ...

CVE-2022-23408

CRITICAL CVSS 9.1 Jan 18, 2022

This vulnerability in wolfSSL allows attackers to decrypt TLS/DTLS traffic when using AES-CBC or DES3 without AEAD protection. It affects systems using wolfSSL 5.x before 5.1.1 for TLS 1.1/1.2 or DTLS...

CVE-2021-37155

CRITICAL CVSS 9.8 Jul 21, 2021

This vulnerability in wolfSSL allows attackers to bypass OCSP (Online Certificate Status Protocol) validation by providing mismatched serial numbers between requests and responses. This could enable m...

CVE-2020-36177

CRITICAL CVSS 9.8 Jan 6, 2021

This vulnerability in wolfSSL's RSA-PSS padding implementation allows an out-of-bounds write when processing certain cryptographic operations. Attackers can exploit this to execute arbitrary code or c...

CVE-2025-12888

HIGH CVSS 7.5 Nov 21, 2025

This vulnerability allows attackers to extract private keys from X25519 cryptographic implementations on Xtensa-based ESP32 chips through timing side-channel attacks. The issue stems from compiler opt...

CVE-2025-11931

HIGH CVSS 8.2 Nov 21, 2025

An integer underflow vulnerability in wolfSSL's XChaCha20-Poly1305 decryption function allows attackers to cause out-of-bounds memory access when processing maliciously crafted data. This affects appl...

CVE-2025-11935

HIGH CVSS 7.5 Nov 21, 2025

This TLS 1.3 vulnerability allows malicious servers to bypass perfect forward secrecy (PFS) requirements when using pre-shared keys (PSK). Clients may unknowingly establish connections without PFS, re...

CVE-2024-5991

HIGH CVSS 7.5 Aug 27, 2024

CVE-2024-5991 is an out-of-bounds read vulnerability in wolfSSL's X509 certificate hostname validation. Attackers can cause the library to read beyond allocated memory boundaries when processing non-N...

CVE-2022-25640

HIGH CVSS 7.5 Feb 24, 2022

This vulnerability in wolfSSL allows TLS 1.3 clients to bypass mutual authentication requirements by omitting the certificate_verify message during handshake. It affects servers using wolfSSL for TLS ...

CVE-2025-12889

MEDIUM CVSS 5.4 Nov 22, 2025

This TLS 1.2 vulnerability allows clients to use weaker cryptographic digests during certificate authentication than what the server requested, potentially enabling downgrade attacks. It affects syste...

CVE-2025-11933

MEDIUM CVSS 6.5 Nov 21, 2025

A vulnerability in wolfSSL's TLS 1.3 CKS extension parsing allows remote attackers to cause denial-of-service by sending crafted ClientHello messages with duplicate CKS extensions. This affects wolfSS...

CVE-2025-11936

MEDIUM CVSS 5.3 Nov 21, 2025

A denial-of-service vulnerability in wolfSSL v5.8.2 allows remote attackers to crash TLS 1.3 connections by sending malicious ClientHello messages with duplicate KeyShareEntry values. This affects any...

CVE-2025-7396

MEDIUM CVSS 4.6 Jul 18, 2025

CVE-2025-7396 is a side-channel vulnerability in wolfSSL 5.8.2 where Curve25519 blinding is enabled by default only for C implementations, leaving ARM/Intel assembly builds and small Curve25519 featur...

CVE-2024-1545

MEDIUM CVSS 5.9 Aug 29, 2024

This CVE describes a fault injection vulnerability in the RsaPrivateDecryption function of WolfSSL, allowing a co-resident attacker on the same system to potentially disclose sensitive information or ...

CVE-2024-5814

MEDIUM CVSS 5.3 Aug 27, 2024

This TLS protocol vulnerability allows a malicious TLS 1.2 server to force a TLS 1.3 client with downgrade capability to use an unintended ciphersuite, potentially enabling downgrade attacks. It affec...