PatchSiren cyber security CVE debrief
CVE-2026-81019 wolfSSL Inc. CVE debrief
The wolfProvider before version 1.2.2 has a vulnerability where it generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. This results in every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection being encrypted under an identical key and nonce pair, disclosing the keystream and leaking the GHASH authentication key. Users of wolfProvider before version 1.2.2, especially those using TLS 1.2 and DTLS 1.2 with AES-GCM encryption, should take immediate action to update to version 1.2.2 or later. The vulnerability allows for authentication tag forgery, which can lead to serious security breaches. Affected users should review and update their inventory of affected systems and implement compensating controls such as monitoring for suspicious activity.
- Vendor
- wolfSSL Inc.
- Product
- wolfProvider
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-28
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-08-28
- Advisory updated
- 2026-09-01
Who should care
Users of wolfProvider before version 1.2.2, especially those using TLS 1.2 and DTLS 1.2 with AES-GCM encryption, should take immediate action to update to version 1.2.2 or later. The vulnerability allows for authentication tag forgery, which can lead to serious security breaches. Affected users should review and update their inventory of affected systems and implement compensating controls such as monitoring for suspicious activity. Security teams and operators should prioritize this update to prevent potential security breaches. Vulnerability management and platform teams should also review the affected scope and severity to ensure proper mitigation. This vulnerability has a high CVSS score of 7.4, indicating a high severity level. Therefore, it is crucial for affected users to take immediate action to mitigate the vulnerability. Additionally, users should verify their systems for potential exposure and review compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection logs should also be checked for exposed assets that need extra review. Exceptions should be tracked, and remediated assets should be retested before closing the item, with evidence documented. Asset inventory and security teams should also be involved in the remediation process to ensure that all affected systems are properly updated or mitigated. Rollback and change windows should be considered for updates to ensure minimal disruption. Source tracking and verification should also be performed to confirm the effectiveness of the remediation efforts. Overall, a comprehensive approach is necessary to address this vulnerability and prevent potential security breaches. This may involve coordination between multiple teams, including security, operations, and IT, to ensure that all affected systems are properly mitigated and that the vulnerability is fully remediated. By taking a proactive and thorough approach, organizations can minimize the risk associated with this vulnerability and protect their systems and data from potential attacks. The remediation process should be carefully planned and executed to ensure that all necessary steps are taken to
Technical summary
The wolfProvider before version 1.2.2 has a vulnerability where it generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. This results in every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection being encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream and leaks the GHASH authentication key, enabling authentication tag forgery.
Defensive priority
Immediate attention recommended due to high CVSS score of 7.4 and potential for authentication tag forgery.
Recommended defensive actions
- Update wolfProvider to version 1.2.2 or later
- Implement compensating controls such as monitoring for suspicious activity
- Review and update inventory of affected systems
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The wolfProvider before version 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. This results in every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection being encrypted under an identical key and nonce pair, disclosing the keystream and leaking the GHASH authentication key.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81019 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81019
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81019 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81019
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.wolfssl.com/docs/security-vulnerabilities/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.