Vulnerability index

Browse CVEs

133 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-co… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-7511 PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged sign… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-7532 iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowi… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-8720 wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of th… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destinati… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-55962 TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificat… Wolfssl 5.9.2+ Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-6329 PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be … Wolfssl 5.9.2+ Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-6330 The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakeni… Wolfssl 5.9.2+ Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-6092 When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC. Wolfssl 5.9.2+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cac… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the targe… Wolfssl 5.9.2+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-6679 A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to… Wolfssl 5.9.1+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-6731 X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption. Wolfssl 5.9.2+ Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-6681 The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provi… Wolfssl 5.9.1+ Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-6450 A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unh… Wolfssl 5.9.2+ Fix from $1,6002026-06-25 CRITICAL 9.8 CVE-2026-7531 Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server… Wolfssl 5.9.2+ Fix from $2,3002026-06-25 HIGH 7.5 CVE-2026-55958 Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_S… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-55960 Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so Pars… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-55964 Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage … Wolfssl 5.9.2+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-10097 wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during the Fujisaki-Okamoto re-encryp… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-10512 The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so the computed result may not … Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-11310 X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opens… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-12340 Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Iden… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-10592 Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rej… Wolfssl 5.9.2+ Fix from $1,6002026-06-25 CRITICAL 9.1 CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supp… Wolfssl 5.9.2+ Fix from $2,3002026-06-25 HIGH 7.5 CVE-2026-55961 wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object has empty signerInfos, s… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-55967 AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowi… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-6091 Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted … Wolfssl 5.9.2+ Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-6291 Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned d… Wolfssl 5.9.2+ Fix from $1,6002026-06-25