Technology · Wolfssl
wolfSSL vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 44 vulnerabilities in wolfSSL: 0 in the last 7 days and 0 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-8720, was published on 25 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 2
- Exploited in the wild
- 0
About wolfSSL
wolfSSL is a lightweight, portable, C-language-based SSL/TLS library targeted at IoT, embedded, and RTOS environments.
Latest wolfSSL vulnerabilities
- CVE-2026-8720: wolfSSL HMAC-BLAKE2 message integrity bypass via oversized keysinfoCVSS 5.9
- CVE-2026-7532: wolfSSL IP address name constraints bypass when WOLFSSL_IP_ALT_NAME is undefinedinfoCVSS 5.7
- CVE-2026-7511: wolfSSL improper signature verification in PKCS7_verifyinfoCVSS 5.9
- CVE-2026-6331: wolfSSL HMAC zero-length tag forgery in EVP_DigestVerifyFinalinfoCVSS 2.1
- CVE-2026-6330: wolfSSL ML-KEM partial ciphertext comparison on ARM64 NEONinfoCVSS 6.3
- CVE-2026-6329: wolfSSL improper MAC verification in PKCS#12infoCVSS 6
- CVE-2026-6325: wolfSSL out-of-bounds write in SetSuitesHashSigAlgoinfoCVSS 2
- CVE-2026-6092: wolfSSL algorithm downgrade from Encrypt-then-MAC to MAC-then-EncryptinfoCVSS 2.1
- CVE-2026-55962: wolfSSL improper authentication in TLS 1.3 post-handshake authenticationinfoCVSS 6
- CVE-2026-11703: wolfSSL improper authentication in session-ID resumptioninfoCVSS 6
- CVE-2026-10098: wolfSSL improper certificate validation in OCSP serial number lookupinfoCVSS 6.3
- CVE-2026-6731: wolfSSL X.509 name constraint bypass in Subject Common NameinfoCVSS 6
- CVE-2026-6681: wolfSSL out-of-bounds write in PKCS#7 decodinginfoCVSS 1
- CVE-2026-6679: wolfSSL heap buffer overflow in DTLS 1.3 ACK serializationinfoCVSS 8.8
- CVE-2026-6678: wolfSSL integer underflow in wc_PKCS7_DecryptOriinfoCVSS 1
- CVE-2026-6450: wolfSSL improper certificate validation in ParseCRL_ExtensionsinfoCVSS 1
- CVE-2026-6412: wolfSSL Use of Broken Cryptography in Certificate ProcessinginfoCVSS 2.3
- CVE-2026-7531: wolfSSL use-after-free in PQC hybrid key-share handlinginfoCVSS 2.3
- CVE-2026-55964: wolfSSL improper certificate validation in OpenSSL compatibility layerinfoCVSS 6.3
- CVE-2026-55960: wolfSSL authentication bypass via un-negotiated Raw Public KeyinfoCVSS 8.2
- CVE-2026-55958: wolfSSL Out-of-bounds Write in Renesas TSIP TLS 1.3 Transcript BufferinfoCVSS 8.3
- CVE-2026-12340: wolfSSL out-of-bounds heap read in SM2/SM3 certificate verificationinfoCVSS 6.3
- CVE-2026-11310: wolfSSL X.509 trust-chain bypass in OpenSSL compatibility layerinfoCVSS 8.7
- CVE-2026-10592: wolfSSL improper certificate validation in CA name constraintsinfoCVSS 6.3
- CVE-2026-10512: wolfSSL incorrect calculation in X25519 x86_64 assembly implementationinfoCVSS 2.3
Most severe wolfSSL vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-5194: wolfSSL improper certificate validation in ECDSA signature verificationcriticalCVSS 9.1EPSS 0.0%
- CVE-2026-5393: wolfSSL out-of-bounds read in dual-algorithm CertificateVerify processingcriticalCVSS 9.1
- CVE-2026-5501: wolfSSL improper certificate validation in OpenSSL compatibility layerhighCVSS 8.1
- CVE-2026-5479: wolfSSL improper authentication tag validation in ChaCha20-Poly1305 decryptionhighCVSS 8.1
- CVE-2026-5466: wolfSSL improper signature verification in ECCSI wc_VerifyEccsiHashhighCVSS 8.1
- CVE-2026-5188: wolfSSL integer underflow in X.509 SAN extension parsinghighCVSS 8.1
- CVE-2026-5477: wolfSSL wolfCrypt integer overflow in CMAC implementationhighCVSS 7.5
- CVE-2026-5263: wolfSSL improper X.509 nameConstraints enforcement in wolfcryptmediumCVSS 6.5EPSS 0.1%
- CVE-2026-5460: wolfSSL heap use-after-free in TLS 1.3 PQC hybrid KeyShare processingmediumCVSS 6.5
- CVE-2026-5500: wolfSSL improper input validation in wc_PKCS7_DecodeAuthEnvelopedDatamediumCVSS 5.9
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/wolfssl.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "wolfSSL vulnerabilities", https://junglewise.ai/threats/technologies/wolfssl, 26 September 2026.