{"schema_version":1,"title":"wolfSSL vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 44 vulnerabilities in wolfSSL: 0 in the last 7 days and 0 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-8720, was published on 25 June 2026.","url":"https://junglewise.ai/threats/technologies/wolfssl","json_url":"https://junglewise.ai/threats/technologies/wolfssl.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/wolfssl","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":44,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":44},"latest":[{"cve":"CVE-2026-8720","cvss":5.9,"slug":"cve-2026-8720-wolfssl-hmac-blake2-message-integrity-bypass-via-oversized-keys","title":"wolfSSL HMAC-BLAKE2 message integrity bypass via oversized keys","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:03.39+00:00","url":"https://junglewise.ai/threats/cve-2026-8720-wolfssl-hmac-blake2-message-integrity-bypass-via-oversized-keys"},{"cve":"CVE-2026-7532","cvss":5.7,"slug":"cve-2026-7532-wolfssl-ip-address-name-constraints-bypass-when-wolfssl-ip-alt","title":"wolfSSL IP address name constraints bypass when WOLFSSL_IP_ALT_NAME is undefined","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:03.263+00:00","url":"https://junglewise.ai/threats/cve-2026-7532-wolfssl-ip-address-name-constraints-bypass-when-wolfssl-ip-alt"},{"cve":"CVE-2026-7511","cvss":5.9,"slug":"cve-2026-7511-wolfssl-improper-signature-verification-in-pkcs7-verify","title":"wolfSSL improper signature verification in PKCS7_verify","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:03.133+00:00","url":"https://junglewise.ai/threats/cve-2026-7511-wolfssl-improper-signature-verification-in-pkcs7-verify"},{"cve":"CVE-2026-6331","cvss":2.1,"slug":"cve-2026-6331-wolfssl-hmac-zero-length-tag-forgery-in-evp-digestverifyfinal","title":"wolfSSL HMAC zero-length tag forgery in EVP_DigestVerifyFinal","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:03.01+00:00","url":"https://junglewise.ai/threats/cve-2026-6331-wolfssl-hmac-zero-length-tag-forgery-in-evp-digestverifyfinal"},{"cve":"CVE-2026-6330","cvss":6.3,"slug":"cve-2026-6330-wolfssl-ml-kem-partial-ciphertext-comparison-on-arm64-neon","title":"wolfSSL ML-KEM partial ciphertext comparison on ARM64 NEON","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:02.887+00:00","url":"https://junglewise.ai/threats/cve-2026-6330-wolfssl-ml-kem-partial-ciphertext-comparison-on-arm64-neon"},{"cve":"CVE-2026-6329","cvss":6,"slug":"cve-2026-6329-wolfssl-improper-mac-verification-in-pkcs-12","title":"wolfSSL improper MAC verification in PKCS#12","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:02.757+00:00","url":"https://junglewise.ai/threats/cve-2026-6329-wolfssl-improper-mac-verification-in-pkcs-12"},{"cve":"CVE-2026-6325","cvss":2,"slug":"cve-2026-6325-wolfssl-out-of-bounds-write-in-setsuiteshashsigalgo","title":"wolfSSL out-of-bounds write in SetSuitesHashSigAlgo","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:02.63+00:00","url":"https://junglewise.ai/threats/cve-2026-6325-wolfssl-out-of-bounds-write-in-setsuiteshashsigalgo"},{"cve":"CVE-2026-6092","cvss":2.1,"slug":"cve-2026-6092-wolfssl-algorithm-downgrade-from-encrypt-then-mac-to-mac-then","title":"wolfSSL algorithm downgrade from Encrypt-then-MAC to MAC-then-Encrypt","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:02.507+00:00","url":"https://junglewise.ai/threats/cve-2026-6092-wolfssl-algorithm-downgrade-from-encrypt-then-mac-to-mac-then"},{"cve":"CVE-2026-55962","cvss":6,"slug":"cve-2026-55962-wolfssl-improper-authentication-in-tls-1-3-post-handshake","title":"wolfSSL improper authentication in TLS 1.3 post-handshake authentication","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:02.26+00:00","url":"https://junglewise.ai/threats/cve-2026-55962-wolfssl-improper-authentication-in-tls-1-3-post-handshake"},{"cve":"CVE-2026-11703","cvss":6,"slug":"cve-2026-11703-wolfssl-improper-authentication-in-session-id-resumption","title":"wolfSSL improper authentication in session-ID resumption","severity":"info","exploited":false,"published_at":"2026-06-25T22:17:00.217+00:00","url":"https://junglewise.ai/threats/cve-2026-11703-wolfssl-improper-authentication-in-session-id-resumption"},{"cve":"CVE-2026-10098","cvss":6.3,"slug":"cve-2026-10098-wolfssl-improper-certificate-validation-in-ocsp-serial-number","title":"wolfSSL improper certificate validation in OCSP serial number lookup","severity":"info","exploited":false,"published_at":"2026-06-25T22:16:59.78+00:00","url":"https://junglewise.ai/threats/cve-2026-10098-wolfssl-improper-certificate-validation-in-ocsp-serial-number"},{"cve":"CVE-2026-6731","cvss":6,"slug":"cve-2026-6731-wolfssl-x-509-name-constraint-bypass-in-subject-common-name","title":"wolfSSL X.509 name constraint bypass in Subject Common Name","severity":"info","exploited":false,"published_at":"2026-06-25T21:16:28.4+00:00","url":"https://junglewise.ai/threats/cve-2026-6731-wolfssl-x-509-name-constraint-bypass-in-subject-common-name"},{"cve":"CVE-2026-6681","cvss":1,"slug":"cve-2026-6681-wolfssl-out-of-bounds-write-in-pkcs-7-decoding","title":"wolfSSL out-of-bounds write in PKCS#7 decoding","severity":"info","exploited":false,"published_at":"2026-06-25T21:16:28.283+00:00","url":"https://junglewise.ai/threats/cve-2026-6681-wolfssl-out-of-bounds-write-in-pkcs-7-decoding"},{"cve":"CVE-2026-6679","cvss":8.8,"slug":"cve-2026-6679-wolfssl-heap-buffer-overflow-in-dtls-1-3-ack-serialization","title":"wolfSSL heap buffer overflow in DTLS 1.3 ACK serialization","severity":"info","exploited":false,"published_at":"2026-06-25T21:16:28.167+00:00","url":"https://junglewise.ai/threats/cve-2026-6679-wolfssl-heap-buffer-overflow-in-dtls-1-3-ack-serialization"},{"cve":"CVE-2026-6678","cvss":1,"slug":"cve-2026-6678-wolfssl-integer-underflow-in-wc-pkcs7-decryptori","title":"wolfSSL integer underflow in wc_PKCS7_DecryptOri","severity":"info","exploited":false,"published_at":"2026-06-25T21:16:28.047+00:00","url":"https://junglewise.ai/threats/cve-2026-6678-wolfssl-integer-underflow-in-wc-pkcs7-decryptori"},{"cve":"CVE-2026-6450","cvss":1,"slug":"cve-2026-6450-wolfssl-improper-certificate-validation-in-parsecrl-extensions","title":"wolfSSL improper certificate validation in ParseCRL_Extensions","severity":"info","exploited":false,"published_at":"2026-06-25T21:16:27.917+00:00","url":"https://junglewise.ai/threats/cve-2026-6450-wolfssl-improper-certificate-validation-in-parsecrl-extensions"},{"cve":"CVE-2026-6412","cvss":2.3,"slug":"cve-2026-6412-wolfssl-use-of-broken-cryptography-in-certificate-processing","title":"wolfSSL Use of Broken Cryptography in Certificate Processing","severity":"info","exploited":false,"published_at":"2026-06-25T21:16:27.797+00:00","url":"https://junglewise.ai/threats/cve-2026-6412-wolfssl-use-of-broken-cryptography-in-certificate-processing"},{"cve":"CVE-2026-7531","cvss":2.3,"slug":"cve-2026-7531-wolfssl-use-after-free-in-pqc-hybrid-key-share-handling","title":"wolfSSL use-after-free in PQC hybrid key-share handling","severity":"info","exploited":false,"published_at":"2026-06-25T20:17:17.763+00:00","url":"https://junglewise.ai/threats/cve-2026-7531-wolfssl-use-after-free-in-pqc-hybrid-key-share-handling"},{"cve":"CVE-2026-55964","cvss":6.3,"slug":"cve-2026-55964-wolfssl-improper-certificate-validation-in-openssl-compatibility","title":"wolfSSL improper certificate validation in OpenSSL compatibility layer","severity":"info","exploited":false,"published_at":"2026-06-25T20:17:16.817+00:00","url":"https://junglewise.ai/threats/cve-2026-55964-wolfssl-improper-certificate-validation-in-openssl-compatibility"},{"cve":"CVE-2026-55960","cvss":8.2,"slug":"cve-2026-55960-wolfssl-authentication-bypass-via-un-negotiated-raw-public-key","title":"wolfSSL authentication bypass via un-negotiated Raw Public Key","severity":"info","exploited":false,"published_at":"2026-06-25T20:17:16.617+00:00","url":"https://junglewise.ai/threats/cve-2026-55960-wolfssl-authentication-bypass-via-un-negotiated-raw-public-key"},{"cve":"CVE-2026-55958","cvss":8.3,"slug":"cve-2026-55958-wolfssl-out-of-bounds-write-in-renesas-tsip-tls-1-3-transcript","title":"wolfSSL Out-of-bounds Write in Renesas TSIP TLS 1.3 Transcript Buffer","severity":"info","exploited":false,"published_at":"2026-06-25T20:17:16.14+00:00","url":"https://junglewise.ai/threats/cve-2026-55958-wolfssl-out-of-bounds-write-in-renesas-tsip-tls-1-3-transcript"},{"cve":"CVE-2026-12340","cvss":6.3,"slug":"cve-2026-12340-wolfssl-out-of-bounds-heap-read-in-sm2-sm3-certificate","title":"wolfSSL out-of-bounds heap read in SM2/SM3 certificate verification","severity":"info","exploited":false,"published_at":"2026-06-25T20:17:09.907+00:00","url":"https://junglewise.ai/threats/cve-2026-12340-wolfssl-out-of-bounds-heap-read-in-sm2-sm3-certificate"},{"cve":"CVE-2026-11310","cvss":8.7,"slug":"cve-2026-11310-wolfssl-x-509-trust-chain-bypass-in-openssl-compatibility-layer","title":"wolfSSL X.509 trust-chain bypass in OpenSSL compatibility layer","severity":"info","exploited":false,"published_at":"2026-06-25T20:17:09.777+00:00","url":"https://junglewise.ai/threats/cve-2026-11310-wolfssl-x-509-trust-chain-bypass-in-openssl-compatibility-layer"},{"cve":"CVE-2026-10592","cvss":6.3,"slug":"cve-2026-10592-wolfssl-improper-certificate-validation-in-ca-name-constraints","title":"wolfSSL improper certificate validation in CA name constraints","severity":"info","exploited":false,"published_at":"2026-06-25T20:17:09.65+00:00","url":"https://junglewise.ai/threats/cve-2026-10592-wolfssl-improper-certificate-validation-in-ca-name-constraints"},{"cve":"CVE-2026-10512","cvss":2.3,"slug":"cve-2026-10512-wolfssl-incorrect-calculation-in-x25519-x86-64-assembly","title":"wolfSSL incorrect calculation in X25519 x86_64 assembly implementation","severity":"info","exploited":false,"published_at":"2026-06-25T20:17:09.513+00:00","url":"https://junglewise.ai/threats/cve-2026-10512-wolfssl-incorrect-calculation-in-x25519-x86-64-assembly"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"wolfSSL","slug":"wolfssl","vendor":{"name":"Wolfssl","slug":"wolfssl","url":"https://junglewise.ai/threats/vendors/wolfssl"},"aliases":[],"category":"library","homepage":"https://www.wolfssl.com/","repo_url":"https://github.com/wolfSSL/wolfssl","description":"wolfSSL is a lightweight, portable, C-language-based SSL/TLS library targeted at IoT, embedded, and RTOS environments.","url":"https://junglewise.ai/threats/technologies/wolfssl"},"most_severe":[{"cve":"CVE-2026-5194","cvss":9.1,"epss":0.0002,"slug":"cve-2026-5194-wolfssl-improper-certificate-validation-in-ecdsa-signature","title":"wolfSSL improper certificate validation in ECDSA signature verification","severity":"critical","exploited":false,"published_at":"2026-04-09T20:16:28.42+00:00","url":"https://junglewise.ai/threats/cve-2026-5194-wolfssl-improper-certificate-validation-in-ecdsa-signature"},{"cve":"CVE-2026-5393","cvss":9.1,"slug":"cve-2026-5393-wolfssl-out-of-bounds-read-in-dual-algorithm-certificateverify","title":"wolfSSL out-of-bounds read in dual-algorithm CertificateVerify processing","severity":"critical","exploited":false,"published_at":"2026-04-10T00:16:35.75+00:00","url":"https://junglewise.ai/threats/cve-2026-5393-wolfssl-out-of-bounds-read-in-dual-algorithm-certificateverify"},{"cve":"CVE-2026-5501","cvss":8.1,"slug":"cve-2026-5501-wolfssl-improper-certificate-validation-in-openssl-compatibility","title":"wolfSSL improper certificate validation in OpenSSL compatibility layer","severity":"high","exploited":false,"published_at":"2026-04-10T04:17:17.23+00:00","url":"https://junglewise.ai/threats/cve-2026-5501-wolfssl-improper-certificate-validation-in-openssl-compatibility"},{"cve":"CVE-2026-5479","cvss":8.1,"slug":"cve-2026-5479-wolfssl-improper-authentication-tag-validation-in-chacha20","title":"wolfSSL improper authentication tag validation in ChaCha20-Poly1305 decryption","severity":"high","exploited":false,"published_at":"2026-04-10T04:17:16.93+00:00","url":"https://junglewise.ai/threats/cve-2026-5479-wolfssl-improper-authentication-tag-validation-in-chacha20"},{"cve":"CVE-2026-5466","cvss":8.1,"slug":"cve-2026-5466-wolfssl-improper-signature-verification-in-eccsi-wc","title":"wolfSSL improper signature verification in ECCSI wc_VerifyEccsiHash","severity":"high","exploited":false,"published_at":"2026-04-10T04:17:16.42+00:00","url":"https://junglewise.ai/threats/cve-2026-5466-wolfssl-improper-signature-verification-in-eccsi-wc"},{"cve":"CVE-2026-5188","cvss":8.1,"slug":"cve-2026-5188-wolfssl-integer-underflow-in-x-509-san-extension-parsing","title":"wolfSSL integer underflow in X.509 SAN extension parsing","severity":"high","exploited":false,"published_at":"2026-04-10T04:17:15.7+00:00","url":"https://junglewise.ai/threats/cve-2026-5188-wolfssl-integer-underflow-in-x-509-san-extension-parsing"},{"cve":"CVE-2026-5477","cvss":7.5,"slug":"cve-2026-5477-wolfssl-wolfcrypt-integer-overflow-in-cmac-implementation","title":"wolfSSL wolfCrypt integer overflow in CMAC implementation","severity":"high","exploited":false,"published_at":"2026-04-10T06:16:05.243+00:00","url":"https://junglewise.ai/threats/cve-2026-5477-wolfssl-wolfcrypt-integer-overflow-in-cmac-implementation"},{"cve":"CVE-2026-5263","cvss":6.5,"epss":0.0015,"slug":"cve-2026-5263-wolfssl-improper-x-509-nameconstraints-enforcement-in-wolfcrypt","title":"wolfSSL improper X.509 nameConstraints enforcement in wolfcrypt","severity":"medium","exploited":false,"published_at":"2026-04-09T22:16:36.647+00:00","url":"https://junglewise.ai/threats/cve-2026-5263-wolfssl-improper-x-509-nameconstraints-enforcement-in-wolfcrypt"},{"cve":"CVE-2026-5460","cvss":6.5,"slug":"cve-2026-5460-wolfssl-heap-use-after-free-in-tls-1-3-pqc-hybrid-keyshare","title":"wolfSSL heap use-after-free in TLS 1.3 PQC hybrid KeyShare processing","severity":"medium","exploited":false,"published_at":"2026-04-10T00:16:36.033+00:00","url":"https://junglewise.ai/threats/cve-2026-5460-wolfssl-heap-use-after-free-in-tls-1-3-pqc-hybrid-keyshare"},{"cve":"CVE-2026-5500","cvss":5.9,"slug":"cve-2026-5500-wolfssl-improper-input-validation-in-wc-pkcs7","title":"wolfSSL improper input validation in wc_PKCS7_DecodeAuthEnvelopedData","severity":"medium","exploited":false,"published_at":"2026-04-10T04:17:17.08+00:00","url":"https://junglewise.ai/threats/cve-2026-5500-wolfssl-improper-input-validation-in-wc-pkcs7"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}