Wolfssl
69 known vulnerabilities
Top Products
wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a
iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced
PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bo
HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC ve
The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's i
PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and all
Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write pas
When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing E
TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the cl
Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for t
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose se
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written
A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. T
Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handlin
A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allow
Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate proce
Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1
Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to ha
Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw pub
Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding th
Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 si
X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects on
Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildca
The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so
wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during t
Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically
Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certi
AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected
wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an ob
X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_
An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to forge CMAC tags. The functi
wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is
wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received a
In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and related EVP cipher fi
wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_
An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certific
A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the err
X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing d
Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-
Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bound
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without vali
A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repe
In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find returned NULL. This
A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc_PKCS7_DecryptOri() function in wolfcrypt/src/
Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption
A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname
Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that
URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification
Frequently Asked Questions
How many CVEs affect Wolfssl?
Wolfssl has 69 CVE records in our database, including 11 critical and 29 high severity vulnerabilities.
What are the most severe Wolfssl vulnerabilities?
Wolfssl has 11 critical severity (CVSS 9.0+) and 29 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Wolfssl vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Wolfssl products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Wolfssl Vulnerabilities
CyberStrike scans your infrastructure for Wolfssl vulnerabilities and provides real-time remediation guidance.
Get Started