LIVE · cybersecurity feed
Live wire
vendor

Wolfssl

34 CVEs published in the last four months and 1 stories. Exploited flaws first.

Critical6
High21
Medium5
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-35489.8criticalwolfsslTwo buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer170d ago
CVE-2026-75319.8criticalwolfsslUse-after-free in PQC hybrid key-share handling.72d ago
CVE-2026-43959.8criticalwolfsslHeap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remo170d ago
CVE-2026-38499.8criticalwolfsslStack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config.170d ago
CVE-2026-35499.8criticalwolfsslHeap Overflow in TLS 1.3 ECH parsing.170d ago
CVE-2026-60949.1criticalwolfsslHeap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData.72d ago
CVE-2026-26468.1highwolfsslA heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function.170d ago
CVE-2026-87207.5highwolfsslwc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, produci72d ago
CVE-2026-559607.5highwolfsslUn-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation.72d ago
CVE-2026-66797.5highwolfsslA heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticat72d ago
CVE-2026-67317.5highwolfsslX.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name.72d ago
CVE-2026-117037.5highwolfsslMissing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed72d ago
CVE-2026-63257.5highwolfsslOut-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a writ72d ago
CVE-2026-63317.5highwolfsslHMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HM72d ago
CVE-2026-75117.5highwolfsslPKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correct72d ago
CVE-2026-75327.5highwolfssliPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined.72d ago
CVE-2026-35477.5highwolfsslOut-of-bounds read in ALPN parsing due to incomplete validation.170d ago
CVE-2026-26457.5highwolfsslIn wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation.170d ago
CVE-2026-119997.5highwolfsslX.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_v72d ago
CVE-2026-559617.5highwolfsslwolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer.72d ago
CVE-2026-559677.5highwolfsslAES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rej72d ago
CVE-2026-100977.5highwolfsslwolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes du72d ago
CVE-2026-105127.5highwolfsslThe X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reducti72d ago
CVE-2026-113107.5highwolfsslX.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()).72d ago
CVE-2026-123407.5highwolfsslOut-of-bounds heap read during SM2/SM3 certificate signature verification.72d ago
CVE-2026-559587.5highwolfsslOut-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer.72d ago
CVE-2026-08197.1highwolfsslA stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality.170d ago
CVE-2026-35795.9mediumwolfsslwolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication170d ago
CVE-2026-32295.5mediumwolfsslAn integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption 170d ago
CVE-2026-10055.3mediumwolfsslInteger underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decr170d ago
CVE-2026-35035.2mediumwolfsslProtection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex170d ago
CVE-2026-35804.7mediumwolfsslIn wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bne170d ago
CVE-2026-41593.3lowwolfssl1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content.170d ago
CVE-2026-32302.7lowwolfsslMissing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead t170d ago

Filter the full tracker by Wolfssl

Our coverage of Wolfssl

CVE-2026-28739high

Multiple Vulnerabilities Found in WolfSSL, GeoVision, and VTK-DICOM

Researchers have disclosed several vulnerabilities affecting WolfSSL, GeoVision, and VTK-DICOM. The issues include improper input validation and integer underflow in WolfSSL, and a range of problems in GeoVision such as memory corruption, OS command injection, buffer overflows, and privilege escalation. These vulnerabilities have been addressed by the respective vendors.