Executive brief
wolfSSL is a security library used to protect data and communications in embedded devices and cloud applications. A flaw in its BLAKE2 hashing component causes the system to ignore the actual message content when a very long security key is used, resulting in a digital signature that does not actually prove the message's integrity. This could allow an attacker to modify data without detection in specific configurations using these newer hashing methods.
Technical details
A vulnerability exists in the HMAC-BLAKE2b and HMAC-BLAKE2s implementations within wolfSSL. When a key longer than the BLAKE2 block size is provided, the functions wc_Blake2bHmacFinal and wc_Blake2sHmacFinal reinitialize the hash state during the key-reduction phase. This reinitialization clobbers the accumulated message data in the running hash state, causing the final MAC to be independent of the input message. An attacker could potentially substitute messages without invalidating the MAC if the application uses oversized keys. The issue was addressed by using a separate hash state for key reduction and ensuring proper zero-padding.
Affected products
- wolfSSL wolfSSL 5.9.0 to 5.9.1
Timeline
- 2026-05-12: patched: Fix merged into master branch via Pull Request 10447
- 2026-06-25: disclosed: CVE-2026-8720 published