PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81019 wolfSSL Inc. CVE debrief

The wolfProvider before version 1.2.2 has a vulnerability where it generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. This results in every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection being encrypted under an identical key and nonce pair, disclosing the keystream and leaking the GHASH authentication key. Users of wolfProvider before version 1.2.2, especially those using TLS 1.2 and DTLS 1.2 with AES-GCM encryption, should take immediate action to update to version 1.2.2 or later. The vulnerability allows for authentication tag forgery, which can lead to serious security breaches. Affected users should review and update their inventory of affected systems and implement compensating controls such as monitoring for suspicious activity.

Vendor
wolfSSL Inc.
Product
wolfProvider
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-28
Original CVE updated
2026-09-01
Advisory published
2026-08-28
Advisory updated
2026-09-01

Who should care

Users of wolfProvider before version 1.2.2, especially those using TLS 1.2 and DTLS 1.2 with AES-GCM encryption, should take immediate action to update to version 1.2.2 or later. The vulnerability allows for authentication tag forgery, which can lead to serious security breaches. Affected users should review and update their inventory of affected systems and implement compensating controls such as monitoring for suspicious activity. Security teams and operators should prioritize this update to prevent potential security breaches. Vulnerability management and platform teams should also review the affected scope and severity to ensure proper mitigation. This vulnerability has a high CVSS score of 7.4, indicating a high severity level. Therefore, it is crucial for affected users to take immediate action to mitigate the vulnerability. Additionally, users should verify their systems for potential exposure and review compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection logs should also be checked for exposed assets that need extra review. Exceptions should be tracked, and remediated assets should be retested before closing the item, with evidence documented. Asset inventory and security teams should also be involved in the remediation process to ensure that all affected systems are properly updated or mitigated. Rollback and change windows should be considered for updates to ensure minimal disruption. Source tracking and verification should also be performed to confirm the effectiveness of the remediation efforts. Overall, a comprehensive approach is necessary to address this vulnerability and prevent potential security breaches. This may involve coordination between multiple teams, including security, operations, and IT, to ensure that all affected systems are properly mitigated and that the vulnerability is fully remediated. By taking a proactive and thorough approach, organizations can minimize the risk associated with this vulnerability and protect their systems and data from potential attacks. The remediation process should be carefully planned and executed to ensure that all necessary steps are taken to

Technical summary

The wolfProvider before version 1.2.2 has a vulnerability where it generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. This results in every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection being encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream and leaks the GHASH authentication key, enabling authentication tag forgery.

Defensive priority

Immediate attention recommended due to high CVSS score of 7.4 and potential for authentication tag forgery.

Recommended defensive actions

  • Update wolfProvider to version 1.2.2 or later
  • Implement compensating controls such as monitoring for suspicious activity
  • Review and update inventory of affected systems
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The wolfProvider before version 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. This results in every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection being encrypted under an identical key and nonce pair, disclosing the keystream and leaking the GHASH authentication key.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81019 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81019

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81019 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81019

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.