Vulnerabilities in wolfssl

94 results
Vexday analysis

WolfSSL apresenta um perfil de risco mínimo com apenas 1 CVE catalogado na base, sem registros de exploração ativa ou vulnerabilidades críticas. A fraqueza identificada (CWE-122 - buffer overflow) é de natureza clássica, porém o risco permanece contido pela baixa exposição histórica do fornecedor e ausência de atividade recente de ataque.

CVE-2026-3230LOWImproper key_share validation in TLS 1.3 HelloRetryRequestEPSS 0.2%CVE-2026-6731MEDIUMX.509 name constraint bypass via Subject CN treated as a DNS nameEPSS 0.2%CVE-2026-10592MEDIUMWildcard DNS SAN bypasses CA name-constraint checksEPSS 0.2%CVE-2026-6091MEDIUMPartial-chain verification accepts untrusted intermediate as trust anchorEPSS 0.2%CVE-2026-5393MEDIUMOOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTSEPSS 0.2%CVE-2025-7396MEDIUMCurve25519 BlindingEPSS 0.2%CVE-2026-55964MEDIUMChain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)EPSS 0.2%CVE-2026-6331LOWHMAC zero-length tag forgery in EVP_DigestVerifyFinalEPSS 0.2%CVE-2026-10098MEDIUMOCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_statusEPSS 0.2%CVE-2024-1543MEDIUMAES T-Table sub-cache-line leakageEPSS 0.2%CVE-2026-5501HIGHImproper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf CertificatesEPSS 0.2%CVE-2026-55967LOWAES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuseEPSS 0.2%CVE-2026-5295MEDIUMStack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OIDEPSS 0.2%CVE-2026-0930LOWPotential wolfSSHd Buffer out-of-bounds Read on Windows Handling Terminal ResizeEPSS 0.2%CVE-2026-5507MEDIUMSession Cache Restore — Arbitrary Free via Deserialized PointerEPSS 0.2%CVE-2026-5263HIGHURI nameConstraints not enforced in ConfirmNameConstraints()EPSS 0.2%CVE-2026-6330MEDIUMML-KEM ARM64 NEON ciphertext comparison only compares half of the inputEPSS 0.2%CVE-2026-5392LOWwolfSSL heap OOB read in PKCS7 SignedData streamingEPSS 0.2%CVE-2026-8720MEDIUMHMAC-BLAKE2 final discards message when key length exceeds block sizeEPSS 0.2%CVE-2025-11934LOWImproper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerifyEPSS 0.2%