wolfSSL
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 167 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 30, 2009 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →PKCS7_verify signer confusion allows forged signatures to be accepted
iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined
HMAC-BLAKE2 final discards message when key length exceeds block size
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify
Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured
Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list
PKCS#12 MAC verification uses attacker-controlled comparison length
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
Monitor wolfSSL in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.