wolfSSL
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 181 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 30, 2009 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Heap use-after-free on read during bidirectional (D)TLS shutdown
OCSP stapling v2 multi accepts non-CA chain certificates as issuers
NameConstraints not enforced across unconstrained intermediate CA
Subject CN name-constraint check bypassed when non-DNS SAN present
Failed X509_verify_cert leaves unverified CA in shared CertManager
Client accepts unsolicited RawPublicKey server certificate type
Trusted peer certificate match ignores public key, allowing forged CA clones
(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
CRL check skipped when OCSP enabled and certificate has no OCSP URL
Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
Monitor wolfSSL in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.