VulnSea

wolfSSL has 12 CVEs on record. Disclosure cadence is accelerating: 11 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-295 (6).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
—
Last 90 days
11 prev 1

Products

  • wolfSSL 12
12
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

wolfSSL vulnerabilities

CVEs affecting wolfSSL, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-93304Medium· 6.3
today

A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange

A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the…

▾ SunlitwolfSSL · wolfSSLvia NVD
CVE-2026-93302High· 8.3
today

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_…

▾ TwilightwolfSSL · wolfSSLvia NVD
CVE-2026-89134Medium· 6.3
today

A certificate with no dNSName SAN but another SAN type present (e.g

A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL …

▾ SunlitwolfSSL · wolfSSLvia NVD
CVE-2026-89136High· 8.3
today

When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication

When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a malicious or misbehaving server to bypass authentication. RPK is off by …

▾ TwilightwolfSSL · wolfSSLvia NVD
CVE-2026-89135Medium· 6.3
today

A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify)

A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version …

▾ SunlitwolfSSL · wolfSSLvia NVD
CVE-2026-94417Low· 2.3
today

When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that carries no Authority Information Access OCSP URL, and accepts a certif…

When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that carries no Authority Information Access OCSP URL, and accepts a certif…

▾ SunlitwolfSSL · wolfSSLvia NVD
CVE-2026-89133Medium· 6.3
today

wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA a…

wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA a…

▾ SunlitwolfSSL · wolfSSLvia NVD
CVE-2026-89102High· 8.3
today

In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery

In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE…

▾ TwilightwolfSSL · wolfSSLvia NVD
CVE-2026-15442Low· 2.3
today

In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free

In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a partial wolfSSL_read() which…

▾ SunlitwolfSSL · wolfSSLvia NVD
CVE-2026-94419Low· 2.3
today

Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() validates it …

Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() validates it …

▾ SunlitwolfSSL · wolfSSLvia NVD
CVE-2026-94418Low· 2.3
today

Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the parse ret…

Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the parse ret…

▾ SunlitwolfSSL · wolfSSLvia NVD
CVE-2026-5263Medium· 6.5
5mo ago

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that vio…

▾ Sunlitwolfssl · wolfsslEPSS 0.25%via NVD
wolfSSL vulnerabilities (CVEs) · VulnSea