vendor
wolfssl
13 thingsrelated by NVD
Its products
wolfssl 10 wolfengine 2 wolfprovider 1
Being told
Watch: its feed Ask more of it
The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.
Every thing
| Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index… CVE-2026-94419 | Severity medium |
| Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory… CVE-2026-94418 | Severity high |
| When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check… CVE-2026-94417 | Severity medium |
| A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at… CVE-2026-93304 | Severity medium |
| MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the… CVE-2026-93302 | Severity high |
| A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in… CVE-2026-89135 | Severity medium |
| A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName… CVE-2026-89134 | Severity critical |
| wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce… CVE-2026-89133 | Severity medium |
| In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can… CVE-2026-89102 | Severity high |
| wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS… CVE-2026-81341 | Severity medium |
| wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record… CVE-2026-81020 | Severity high |
| wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per… CVE-2026-81019 | Severity high |
| In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which… CVE-2026-15442 | Severity medium |