PatchSiren

wolfSSL CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wolfSSL CVE published 2026-06-25

CVE-2026-7532

CVE-2026-7532 is a medium-severity vulnerability in wolfSSL, a popular cryptographic library. The issue arises when the WOLFSSL_IP_ALT_NAME configuration is not defined, allowing IP address name constraints to be bypassed. This could enable a certificate to circumvent an issuing Certificate Authority's (CA) IP address constraints. The Common Vulnerability Scoring System (CVSS) score for this vulnerability [truncated]

LOW wolfSSL CVE published 2026-06-25

CVE-2026-6678

CVE-2026-6678 is an integer underflow vulnerability in the wc_PKCS7_DecryptOri function of wolfSSL, a popular cryptographic library. The vulnerability occurs when handling crafted 'Other Recipient Info', which can lead to incorrect length handling during decryption. This issue was reported with a CVSS score of 1 and a severity of LOW. The CVE was published on June 25, 2026, and modified on July 1, 2026. T [truncated]

HIGH wolfSSL CVE published 2026-04-09

CVE-2026-5263

A vulnerability was discovered in wolfSSL, a popular cryptographic library, where URI nameConstraints from constrained intermediate Certificate Authorities (CAs) are parsed but not enforced during certificate chain verification. This issue, tracked as CVE-2026-5263, allows a compromised or malicious sub-CA to issue leaf certificates with URI Subject Alternative Name (SAN) entries that violate the nameCons [truncated]

CRITICAL wolfSSL CVE published 2026-04-09

CVE-2026-5194

## Summary A critical vulnerability in wolfSSL allows ECDSA signature verification to accept digests smaller than cryptographically appropriate when EdDSA or ML-DSA is also enabled. Missing hash/digest size and OID checks permit undersized digests during ECDSA certificate verification, weakening authentication security when the CA public key is known. ## Technical Details The flaw exists in wolfSSL's sign [truncated]

MEDIUM Wolfssl CVE published 2017-02-24

CVE-2017-6076

CVE-2017-6076 affects wolfSSL versions before 3.10.2. According to the published advisory text, the fp_mul_comba function can make it easier for a malicious user with access to view cache on a machine to extract RSA key information. The issue was published on 2017-02-24 and later NVD metadata confirms the fixed boundary at 3.10.2.