Vulnerabilidades en wolfssl
94 resultadosAnálisis Vexday
WolfSSL apresenta um perfil de risco mínimo com apenas 1 CVE catalogado na base, sem registros de exploração ativa ou vulnerabilidades críticas. A fraqueza identificada (CWE-122 - buffer overflow) é de natureza clássica, porém o risco permanece contido pela baixa exposição histórica do fornecedor e ausência de atividade recente de ataque.
CVE-2026-5479HIGHwolfSSL EVP ChaCha20-Poly1305 AEAD authentication tagEPSS 0.2%CVE-2025-13912LOWPotential non-constant time compiled code with Clang LLVMEPSS 0.1%CVE-2026-5466HIGHwc_VerifyEccsiHash missing sanity checkEPSS 0.1%CVE-2026-55961HIGHwolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signerEPSS 0.1%CVE-2026-5188LOWInteger underflow in X.509 SAN parsing in wolfSSLEPSS 0.1%CVE-2025-12889LOWTLS 1.2 Client Can Downgrade Digest UsedEPSS 0.1%CVE-2026-3580LOWCompiler-induced timing leak in sp_256_get_entry_256_9 on RISC-VEPSS 0.1%CVE-2026-2645MEDIUMAcceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2EPSS 0.1%CVE-2026-2646MEDIUMHeap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() functionEPSS 0.1%CVE-2026-5448LOW1-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBeforeEPSS 0.1%CVE-2026-5504MEDIUMPKCS7 CBC Padding Oracle — Plaintext RecoveryEPSS 0.1%CVE-2026-6412LOWContinued acceptance of SHA-1/MD5 digests in certificate processingEPSS 0.1%CVE-2026-0819LOWStack buffer overflow in PKCS7 SignedData encoding with custom signed attributesEPSS 0.1%CVE-2026-4159LOWwc_PKCS7_DecodeEnvelopedData 1 byte out-of-bounds readEPSS 0.1%