Known Vulnerabilities for products from Wolfssl
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Wolfssl".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94419 json | Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the for... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-94418 json | Not Provided | 2026-09-27 | 2026-09-29 | |
| CVE-2026-94417 json | When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips th... | Not Provided | 2026-09-27 | 2026-09-29 |
| CVE-2026-93302 json | Not Provided | 2026-09-27 | 2026-09-29 | |
| CVE-2026-89135 json | Not Provided | 2026-09-27 | 2026-09-29 | |
| CVE-2026-89134 json | Not Provided | 2026-09-27 | 2026-09-29 | |
| CVE-2026-89133 json | Not Provided | 2026-09-27 | 2026-09-29 | |
| CVE-2026-89102 json | In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapli... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-82208 json | Not Provided | 2026-09-06 | 2026-09-15 | |
| CVE-2026-81341 json | wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer inst... | Not Provided | 2026-08-28 | 2026-09-29 |
| CVE-2026-81020 json | wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments i... | Not Provided | 2026-08-28 | 2026-09-29 |
| CVE-2026-81019 json | wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments... | Not Provided | 2026-08-28 | 2026-09-29 |
| CVE-2026-55967 json | AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by th... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-55964 json | Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have th... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-55962 json | TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client ... | Not Provided | 2026-06-25 | 2026-06-27 |
| CVE-2026-55961 json | wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object ... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-55960 json | Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public k... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-55958 json | Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fix... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-54919 json | Not Provided | 2026-07-10 | 2026-07-14 | |
| CVE-2026-12340 json | Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signatu... | Not Provided | 2026-06-25 | 2026-06-26 |