CVE-2025-12889: TLS 1.2 Client Can Downgrade Digest Used
Published Nov 21, 2025
·Updated
TLS 1.2 Client Can Downgrade Digest Used
Other sources
With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.
— MITRE
Affected Software
1 affected component
wolfSSL wolfssl=5.8.4
Remediation
Patch Available
Event History
Nov 21, 2025
CVE Published
via MITRE·11:06 PM
Data Sourced
via MITRE·11:06 PM
DescriptionWeakness
Nov 22, 2025
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 25, 2025
Data Sourced
via Microsoft·01:02 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-12889?
CVE-2025-12889 is classified as a moderate severity vulnerability due to potential risks associated with weaker digest algorithms in TLS 1.2 connections.
2
How do I fix CVE-2025-12889?
To fix CVE-2025-12889, update to the latest version of wolfSSL that addresses this vulnerability.
3
What software is affected by CVE-2025-12889?
CVE-2025-12889 specifically affects version 5.8.4 of wolfSSL.
4
What impact does CVE-2025-12889 have on TLS 1.2 connections?
CVE-2025-12889 allows a client to downgrade the digest algorithm used, potentially compromising connection security.
5
Is CVE-2025-12889 related to any other vulnerabilities?
CVE-2025-12889 is a standalone vulnerability but highlights broader issues around the security standards in TLS implementations.