CVE-2026-93304: (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server's Finished against that same key. An out-of-order ChangeCipherSpec can therefore be used by an attacker to complete the handshake in place of the server and send data the client accepts as authentic. The client's own traffic still uses correctly derived keys, so the attacker cannot read it, and the genuine server never completes the handshake. DTLS 1.2 clients are exposed because a datagram read can deliver the out-of-order records on its own. TLS 1.2 clients are exposed when the application supplies received bytes with wolfSSLinject() or enables read ahead. For certificate suites, the attacker must be in a man-in-the-middle position. For PSK (Pre Shared Key) connections, any fake server can succeed without knowing the PSK.
Affected Software
Event History
Frequently Asked Questions
Which client deployments are exposed?
DTLS 1.2 clients are exposed because datagram delivery can present the out-of-order records independently. TLS 1.2 clients are exposed only when the application feeds received bytes through wolfSSL_inject() or has read ahead enabled.
What attacker position is required?
For certificate-based cipher suites, the attacker must be positioned as a man in the middle. For PSK connections, a fake server can complete the attack without knowing the PSK.
Can the attacker read data sent by the client?
No. The client continues to use correctly derived keys for its own outbound traffic, so the attacker cannot read that traffic; the genuine server also never completes the handshake.
What does successful exploitation allow the attacker to do?
The attacker can complete the handshake while impersonating the server and send data that the client accepts as authentic.