| CVE-2026-7531 | 9.8 | critical | wolfssl / wolfssl | Use-after-free in PQC hybrid key-share handling. | 72d ago |
| CVE-2026-4395 | 9.8 | critical | wolfssl / wolfssl | Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remo | 170d ago |
| CVE-2026-3849 | 9.8 | critical | wolfssl / wolfssl | Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. | 170d ago |
| CVE-2026-3549 | 9.8 | critical | wolfssl / wolfssl | Heap Overflow in TLS 1.3 ECH parsing. | 170d ago |
| CVE-2026-3548 | 9.8 | critical | wolfssl / wolfssl | Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer | 170d ago |
| CVE-2026-6094 | 9.1 | critical | wolfssl / wolfssl | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. | 72d ago |
| CVE-2026-2646 | 8.1 | high | wolfssl / wolfssl | A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. | 170d ago |
| CVE-2026-8720 | 7.5 | high | wolfssl / wolfssl | wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, produci | 72d ago |
| CVE-2026-7532 | 7.5 | high | wolfssl / wolfssl | iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. | 72d ago |
| CVE-2026-7511 | 7.5 | high | wolfssl / wolfssl | PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correct | 72d ago |
| CVE-2026-6331 | 7.5 | high | wolfssl / wolfssl | HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HM | 72d ago |
| CVE-2026-6325 | 7.5 | high | wolfssl / wolfssl | Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a writ | 72d ago |
| CVE-2026-11703 | 7.5 | high | wolfssl / wolfssl | Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed | 72d ago |
| CVE-2026-6731 | 7.5 | high | wolfssl / wolfssl | X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. | 72d ago |
| CVE-2026-6679 | 7.5 | high | wolfssl / wolfssl | A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticat | 72d ago |
| CVE-2026-55960 | 7.5 | high | wolfssl / wolfssl | Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. | 72d ago |
| CVE-2026-55958 | 7.5 | high | wolfssl / wolfssl | Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. | 72d ago |
| CVE-2026-12340 | 7.5 | high | wolfssl / wolfssl | Out-of-bounds heap read during SM2/SM3 certificate signature verification. | 72d ago |
| CVE-2026-11310 | 7.5 | high | wolfssl / wolfssl | X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). | 72d ago |
| CVE-2026-10512 | 7.5 | high | wolfssl / wolfssl | The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reducti | 72d ago |
| CVE-2026-10097 | 7.5 | high | wolfssl / wolfssl | wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes du | 72d ago |
| CVE-2026-55967 | 7.5 | high | wolfssl / wolfssl | AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rej | 72d ago |
| CVE-2026-55961 | 7.5 | high | wolfssl / wolfssl | wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. | 72d ago |
| CVE-2026-11999 | 7.5 | high | wolfssl / wolfssl | X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_v | 72d ago |
| CVE-2026-3547 | 7.5 | high | wolfssl / wolfssl | Out-of-bounds read in ALPN parsing due to incomplete validation. | 170d ago |
| CVE-2026-2645 | 7.5 | high | wolfssl / wolfssl | In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. | 170d ago |
| CVE-2026-0819 | 7.1 | high | wolfssl / wolfssl | A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. | 170d ago |
| CVE-2026-3579 | 5.9 | medium | wolfssl / wolfssl | wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication | 170d ago |
| CVE-2026-3229 | 5.5 | medium | wolfssl / wolfssl | An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption | 170d ago |
| CVE-2026-1005 | 5.3 | medium | wolfssl / wolfssl | Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decr | 170d ago |
| CVE-2026-3503 | 5.2 | medium | wolfssl / wolfssl | Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex | 170d ago |
| CVE-2026-3580 | 4.7 | medium | wolfssl / wolfssl | In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bne | 170d ago |
| CVE-2026-4159 | 3.3 | low | wolfssl / wolfssl | 1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. | 170d ago |
| CVE-2026-3230 | 2.7 | low | wolfssl / wolfssl | Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead t | 170d ago |