Where
-Infinity
0

wolfSSL wolfsslPKCS7_verify signer confusion allows forged signatures to be accepted

Risk 43
Severity
5.9
First published (updated )

wolfSSL wolfssliPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined

Risk 43
Severity
5.7
First published (updated )

wolfSSL wolfsslHMAC-BLAKE2 final discards message when key length exceeds block size

Risk 31
Severity
5.9
EPSS
0.11%
First published (updated )

wolfSSL wolfSSL_OCSP_resp_find_statusOCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status

Risk 29
Severity
6.3
First published (updated )

TLS session resumptionMissing SNI/ALPN binding on stateful (session-ID) TLS session resumption

Risk 43
Severity
6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

wolfSSL wolfsslTLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify

Risk 38
Severity
6
First published (updated )

OpenSSL Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured

Risk 27
Severity
2.1
First published (updated )

wolfSSL wolfsslOut-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list

Risk 43
Severity
2
First published (updated )

PKCS#12PKCS#12 MAC verification uses attacker-controlled comparison length

Risk 38
Severity
6
First published (updated )

ML-KEM (Kyber) ARM64 NEON ciphertext comparisonML-KEM ARM64 NEON ciphertext comparison only compares half of the input

Risk 40
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL OpenSSLHMAC zero-length tag forgery in EVP_DigestVerifyFinal

Risk 43
Severity
2.1
First published (updated )

wolfSSL wolfsslContinued acceptance of SHA-1/MD5 digests in certificate processing

Risk 22
Severity
2.3
First published (updated )

OpenSSL ParseCRL_ExtensionsCRL critical extension bypass in ParseCRL_Extensions

Risk 27
Severity
1
First published (updated )

CyaSSL wc_PKCS7Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info

Risk 27
Severity
1
First published (updated )

wolfSSL wolfsslDTLS 1.3 ACK serialization heap buffer overflow via integer truncation

Risk 57
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

wolfSSL wolfsslPKCS#7 decode ignores caller output buffer size, writing past buffer bounds

Risk 27
Severity
1
First published (updated )

wolfSSL wolfsslX.509 name constraint bypass via Subject CN treated as a DNS name

Risk 43
Severity
6
First published (updated )

PQUse-after-free in PQC hybrid key-share handling

Risk 86
Severity
2.3
First published (updated )

wolfSSL wolfsslML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery

Risk 49
Severity
8.3
First published (updated )

X25519 x86_64 assemblyX25519 x86_64 assembly final reduction leaves non-canonical field element

Risk 43
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

wolfSSL wolfsslWildcard DNS SAN bypasses CA name-constraint checks

Risk 29
Severity
6.3
First published (updated )

wolfSSL wolfsslX.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring

Risk 47
Severity
8.7
First published (updated )

OpenSSL OpenSSLOut-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation

Risk 43
Severity
6.3
First published (updated )

Renesas WOLFSSL (Renesas TSIP TLS port)Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage

Risk 52
Severity
8.3
First published (updated )

OpenSSL OpenSSLUn-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation

Risk 43
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

wolfSSL wolfsslChain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)

Risk 29
Severity
6.3
First published (updated )

wolfSSLX.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()

Risk 43
Severity
8.2
First published (updated )

wolfSSL wolfsslAES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse

Risk 43
Severity
2
First published (updated )

wolfSSL wolfSSL (OpenSSL compatibility builds)wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer

Risk 43
Severity
8.2
First published (updated )

OpenSSL OpenSSLPartial-chain verification accepts untrusted intermediate as trust anchor

Risk 38
Severity
6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203