wolfssl
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting wolfssl.
- CVE-2026-15442Heap use-after-free on read during bidirectional (D)TLS shutdown
- CVE-2026-89102OCSP stapling v2 multi accepts non-CA chain certificates as issuers
- CVE-2026-89133NameConstraints not enforced across unconstrained intermediate CA
- CVE-2026-89134Subject CN name-constraint check bypassed when non-DNS SAN present
- CVE-2026-89135Failed X509_verify_cert leaves unverified CA in shared CertManager
- CVE-2026-89136Client accepts unsolicited RawPublicKey server certificate type
- CVE-2026-93302Trusted peer certificate match ignores public key, allowing forged CA clones
- CVE-2026-93304(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
- CVE-2026-94417CRL check skipped when OCSP enabled and certificate has no OCSP URL
- CVE-2026-94418Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
- CVE-2026-94419Client session cache reference poisoning allows resumption with wrong server
- CVE-2026-7511PKCS7_verify signer confusion allows forged signatures to be accepted7.5
- CVE-2026-7532iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined7.5
- CVE-2026-8720HMAC-BLAKE2 final discards message when key length exceeds block size7.5
- CVE-2026-10098OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status5.3