Known Vulnerabilities for products from WolfSSL

Listed below are 20 of the newest known vulnerabilities associated with the vendor "WolfSSL".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-94419 json Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the for... Not Provided 2026-09-27 2026-09-30
CVE-2026-94418 json Not Provided 2026-09-27 2026-09-29
CVE-2026-94417 json When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips th... Not Provided 2026-09-27 2026-09-29
CVE-2026-93302 json Not Provided 2026-09-27 2026-09-29
CVE-2026-89135 json Not Provided 2026-09-27 2026-09-29
CVE-2026-89134 json Not Provided 2026-09-27 2026-09-29
CVE-2026-89133 json Not Provided 2026-09-27 2026-09-29
CVE-2026-89102 json In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapli... Not Provided 2026-09-27 2026-09-30
CVE-2026-82208 json Not Provided 2026-09-06 2026-09-15
CVE-2026-81341 json wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer inst... Not Provided 2026-08-28 2026-09-29
CVE-2026-81020 json wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments i... Not Provided 2026-08-28 2026-09-29
CVE-2026-81019 json wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments... Not Provided 2026-08-28 2026-09-29
CVE-2026-55967 json AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by th... Not Provided 2026-06-25 2026-06-26
CVE-2026-55964 json Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have th... Not Provided 2026-06-25 2026-06-26
CVE-2026-55962 json TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client ... Not Provided 2026-06-25 2026-06-27
CVE-2026-55961 json wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object ... Not Provided 2026-06-25 2026-06-26
CVE-2026-55960 json Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public k... Not Provided 2026-06-25 2026-06-26
CVE-2026-55958 json Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fix... Not Provided 2026-06-25 2026-06-26
CVE-2026-54919 json Not Provided 2026-07-10 2026-07-14
CVE-2026-12340 json Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signatu... Not Provided 2026-06-25 2026-06-26

Known software with vulnerabilities from WolfSSL

Type Vendor Product Version
ApplicationWolfsslWolfssl0.5
ApplicationWolfsslYassl0.0.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report