Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.

wolfSSL_jll

JLSEC-2026-758Medium 5.7UpstreamiPAddress name constraints bypass when `WOLFSSL_IP_ALT_NAME` is not definedJLSEC-2026-756Medium 5.9Upstream`PKCS7_verify` signer confusion allows forged signatures, where the signer associated wit…JLSEC-2026-749Low 2.1UpstreamHMAC zero-length tag forgery in `EVP_DigestVerifyFinal`, where a zero-length tag could be…JLSEC-2026-748Medium 6.3UpstreamThe ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the…JLSEC-2026-747Medium 6.0UpstreamPKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the int…JLSEC-2026-746Low 2.0UpstreamOut-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algori…JLSEC-2026-743Low 2.1UpstreamWhen `HAVE_ENCRYPT_THEN_MAC` is configured, the implementation could fall back to MAC-the…JLSEC-2026-737Medium 6.0UpstreamTLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's …JLSEC-2026-698Medium 6.0UpstreamMissing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped th…JLSEC-2026-694Medium 6.3UpstreamOCSP CertID serial-number length-confusion in `wolfSSL_OCSP_resp_find_status` allows a sa…JLSEC-2026-755Medium 6.0UpstreamX.509 name constraint bypass via the Subject Common Name when treated as a DNS-type nameJLSEC-2026-754Low 1.0UpstreamThe PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowin…JLSEC-2026-753High 8.8UpstreamA heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the conn…JLSEC-2026-752Low 1.0UpstreamInteger underflow in `wc_PKCS7_DecryptOri` when handling crafted Other Recipient Info, le…JLSEC-2026-751Low 1.0UpstreamA CRL critical extension bypass exists in `ParseCRL_Extensions` where critical extensions…JLSEC-2026-750Low 2.3UpstreamCertificate policy and RFC 8446 compliance concerns regarding the continued acceptance of…JLSEC-2026-757Low 2.3UpstreamUse-after-free in PQC hybrid key-share handlingJLSEC-2026-738Medium 6.3UpstreamChain intermediate CA:TRUE without keyCertSign accepted as a signing CAJLSEC-2026-735High 8.2UpstreamUn-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypass…JLSEC-2026-734High 8.3UpstreamOut-of-bounds write in the Renesas TSIP TLS 1.3 transcript bufferJLSEC-2026-700Medium 6.3UpstreamOut-of-bounds heap read during SM2/SM3 certificate signature verificationJLSEC-2026-697High 8.7UpstreamX.509 trust-chain bypass in the OpenSSL compatibility certificate verifier...JLSEC-2026-696Medium 6.3UpstreamCertificates with wildcard DNS SANs (e.gJLSEC-2026-695Low 2.3UpstreamThe X25519 `x86_64` assembly implementation fails to clear the most significant bit durin…JLSEC-2026-693High 8.3UpstreamML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks …JLSEC-2026-745Medium 6.0UpstreamBleichenbacher padding oracle in PKCS#7 KTRI decryptionJLSEC-2026-744Medium 6.3UpstreamHeap buffer overread in `wc_PKCS7_DecodeEnvelopedData` when parsing crafted PKCS7 Envelop…JLSEC-2026-742Medium 6.0UpstreamPartial-chain certificate verification may accept chains that terminate at a peer-supplie…JLSEC-2026-739Low 2.0UpstreamAES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 G…JLSEC-2026-736High 8.2Upstream`wolfSSL_PKCS7_verify()` returning success for a degenerate (certs-only) PKCS#7 object th…JLSEC-2026-699High 8.2UpstreamX.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate…JLSEC-2026-727High 8.2UpstreamAn integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited…JLSEC-2026-730High 8.6Upstream`wolfSSL_X509_verify_cert` in the OpenSSL compatibility layer accepts a certificate chain…JLSEC-2026-729High 8.7UpstreamwolfSSL's `wc_PKCS7_DecodeAuthEnvelopedData()` does not properly sanitize the AES-GCM aut…JLSEC-2026-728High 7.6UpstreamIn wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in `wolfSSL_EVP_Cipher…JLSEC-2026-726High 7.6UpstreamwolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars f…JLSEC-2026-715Low 2.3UpstreamAn integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (S…JLSEC-2026-725Medium 6.3UpstreamA heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid …JLSEC-2026-724Low 2.3UpstreamX.509 date buffer overflow in `wolfSSL_X509_notAfter` / `wolfSSL_X509_notBefore`JLSEC-2026-721Medium 6.3UpstreamDual-Algorithm CertificateVerify out-of-bounds readJLSEC-2026-720Low 2.3UpstreamHeap out-of-bounds read in PKCS7 parsingJLSEC-2026-733Medium 4.1UpstreamWhen restoring a session from cache, a pointer from the serialized session data is used i…JLSEC-2026-732Medium 6.3UpstreamA padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to…JLSEC-2026-731Medium 6.9UpstreamIn `TLSX_EchChangeSNI`, the ctx->extensions branch set extensions unconditionally even wh…JLSEC-2026-719Medium 5.9UpstreamNo summary availableJLSEC-2026-741Low 2.1UpstreamInteger underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a progra…JLSEC-2026-740Low 2.1UpstreamA 1-byte stack buffer over-read was identified in the MatchDomainName function (`src/inte…JLSEC-2026-718High 8.3UpstreamHeap buffer overflow in DTLS 1.3 ACK message processingJLSEC-2026-717High 7.0UpstreamNo summary availableJLSEC-2026-723Medium 6.3UpstreamHeap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusionJLSEC-2026-722Medium 6.0UpstreamIn wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byt…JLSEC-2026-716Critical 9.3UpstreamMissing hash/digest size and OID checks allow digests smaller than allowed when verifying…JLSEC-2026-714Low 2.3UpstreamNo summary availableJLSEC-2026-712Low 1.2UpstreamNo summary availableJLSEC-2026-713Low 1.3UpstreamNo summary availableJLSEC-2026-711Medium 6.9UpstreamStack Buffer Overflow in `wc_HpkeLabeledExtract` via Oversized ECH ConfigJLSEC-2026-708High 8.3UpstreamNo summary availableJLSEC-2026-706High 7.5UpstreamOut-of-bounds read in ALPN parsing due to incomplete validationJLSEC-2026-704Low 1.2UpstreamMissing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake log…JLSEC-2026-703Low 1.2UpstreamNo summary availableJLSEC-2026-710Low 2.1UpstreamNo summary availableJLSEC-2026-709Low 2.1UpstreamNo summary availableJLSEC-2026-705Medium 4.3UpstreamProtection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA…JLSEC-2026-707High 7.2UpstreamTwo buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL nu…JLSEC-2026-702Medium 5.0UpstreamA heap-buffer-overflow vulnerability exists in wolfSSL's `wolfSSL_d2i_SSL_SESSION()` func…JLSEC-2026-701Medium 5.5UpstreamNo summary availableJLSEC-2026-692Low 2.1UpstreamInteger underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer…JLSEC-2026-691Low 2.2UpstreamA stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding funct…JLSEC-2026-688Low 1.0UpstreamMultiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed…JLSEC-2026-687Low 2.3UpstreamWith TLS 1.2 connections a client can use any digest, specifically a weaker digest that i…JLSEC-2026-686Low 2.1UpstreamInteger Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 DecryptJLSEC-2026-690Critical 9.2UpstreamA certificate verification error in wolfSSL when building with the `WOLFSSL_SYS_CA_CERTS`…JLSEC-2026-689High 7.0UpstreamIn the OpenSSL compatibility layer implementation, the function `RAND_poll()` was not beh…JLSEC-2026-681Medium 5.5UpstreamThe side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects…JLSEC-2026-685Critical 10.0UpstreamIn function MatchDomainName(), input param str is treated as a NULL terminated string des…JLSEC-2026-684Medium 5.1UpstreamA malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ci…JLSEC-2026-683Medium 5.9UpstreamAn issue was discovered in wolfSSL before 5.7.0JLSEC-2026-682Medium 4.9UpstreamGenerating the ECDSA nonce k samples a random number r and then truncates this randomness…JLSEC-2026-680Critical 9.1UpstreamRemotely executed SEGV and out of bounds read allows malicious packet sender to crash or …JLSEC-2026-678Critical 9.1UpstreamIn wolfSSL prior to 5.6.6, if callback functions are enabled (via the `WOLFSSL_CALLBACKS`…JLSEC-2026-679Medium 5.3UpstreamwolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key b…JLSEC-2026-677Medium 5.9UpstreamwolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation …JLSEC-2026-676High 8.8UpstreamIf a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share ex…JLSEC-2026-674Critical 9.1UpstreamNo summary availableJLSEC-2026-675Medium 5.3UpstreamNo summary availableJLSEC-2026-673High 7.5UpstreamNo summary availableJLSEC-2026-668Medium 5.9UpstreamNo summary availableJLSEC-2026-672High 7.5UpstreamNo summary availableJLSEC-2026-671High 7.5UpstreamNo summary availableJLSEC-2026-670High 7.5UpstreamNo summary availableJLSEC-2026-669Medium 6.5UpstreamNo summary available