CVE-2026-55967: AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse
Published Jun 25, 2026
·Updated
AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent plaintext recovery.
Affected Software
1 affected component
wolfSSL wolfssl>=4.8.0<5.9.2
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-55967?
The severity of CVE-2026-55967 is categorized as low with a CVSS score of 4.0.
2
How do I fix CVE-2026-55967?
To fix CVE-2026-55967, apply the available patch from wolfSSL.
3
What is the impact of CVE-2026-55967?
CVE-2026-55967 allows for potential counter wrap and keystream reuse due to improper handling of large cumulative message sizes.
4
Which software is affected by CVE-2026-55967?
CVE-2026-55967 affects the wolfSSL library.
5
When was CVE-2026-55967 published?
CVE-2026-55967 was published on June 25, 2026.