PatchSiren

wolfSSL Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wolfSSL Inc. CVE published 2026-08-28

CVE-2026-81341

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T16:18:29.483Z and has not been modified since then. wolfEngine before 1.4.1 incorrectly sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number. This results in identical key and nonce pairs for all AES-CCM records within [truncated]

HIGH wolfSSL Inc. CVE published 2026-08-28

CVE-2026-81020

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T16:18:28.890Z and has not been modified since then. The wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. This results in every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection being encrypted under an [truncated]

HIGH wolfSSL Inc. CVE published 2026-08-28

CVE-2026-81019

The wolfProvider before version 1.2.2 has a vulnerability where it generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. This results in every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection being encrypted under an identical key and nonce pair, disclosing the keystream and leaking the GHASH authentication key. Users of wolfProvider befo [truncated]