wolfSSL records
153 published records for vendor wolfssl.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 1.3%
- Pre-auth RCE
- 3
- With a fix record
- 68.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-295 Improper Certificate Validation21
- CWE-787 Out-of-bounds Write16
- CWE-125 Out-of-bounds Read14
- CWE-203 Observable Discrepancy11
- CWE-122 Heap-based Buffer Overflow9
- CWE-20 Improper Input Validation8
The weakness classes this vendor ships most often: where to look.
CWEAll records
153 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2009-4484Weaponized | Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqoracle · mysql · CWE-787 | High7.5 | — | 69.6% | Dec 30, 2009 |
42Plan | CVE-2019-11873No exploit | wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size.wolfssl · wolfssl · CWE-787 | Critical9.8 | — | 8.8% | May 23, 2019 |
42Plan | CVE-2017-2800Proof of concept | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certifwolfssl · wolfssl · CWE-295 | Critical9.8 | — | 8.5% | May 24, 2017 |
40Plan | CVE-2020-36177No exploit | RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest swolfssl · wolfssl · CWE-787 | Critical9.8 | — | 3.5% | Jan 6, 2021 |
40Plan | CVE-2014-2896No exploit | The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified wolfssl · wolfssl · CWE-125 | Critical9.8 | — | 2.8% | Jan 28, 2020 |
40Plan | CVE-2014-2897No exploit | The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows rewolfssl · wolfssl · CWE-125 | Critical9.8 | — | 2.8% | Jan 28, 2020 |
40Plan | CVE-2014-2898No exploit | wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggerswolfssl · wolfssl · CWE-125 | Critical9.8 | — | 2.8% | Jan 28, 2020 |
40Plan | CVE-2019-6439No exploit | examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.wolfssl · wolfssl · CWE-787 | Critical9.8 | — | 2.6% | Jan 15, 2019 |
40Plan | CVE-2024-5991No exploit | Buffer overread in domain name matchingwolfssl · wolfssl · CWE-125 | Critical10.0 | — | 0.6% | Aug 27, 2024 |
39Monitor | CVE-2021-37155No exploit | wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the seriawolfssl · wolfssl | Critical9.8 | — | 1.5% | Jul 21, 2021 |
39Monitor | CVE-2019-16748No exploit | In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking.wolfssl · wolfssl · CWE-125 | Critical9.8 | — | 1.2% | Sep 24, 2019 |
39Monitor | CVE-2019-15651No exploit | wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN bytewolfssl · wolfssl · CWE-125 | Critical9.8 | — | 1.0% | Aug 26, 2019 |
37Monitor | CVE-2022-42905No exploit | In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attawolfssl · wolfssl · CWE-125 | Critical9.1 | — | 2.1% | Nov 6, 2022 |
37Monitor | CVE-2026-5194No exploit | wolfSSL ECDSA Certificate Verificationwolfssl · wolfssl · CWE-295 | Critical9.3 | — | 0.3% | Apr 9, 2026 |
36Monitor | CVE-2022-23408No exploit | wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations.wolfssl · wolfssl · CWE-330 | Critical9.1 | — | 1.4% | Jan 18, 2022 |
36Monitor | CVE-2024-0901No exploit | SEGV and out of bounds memory read from malicious packetwolfssl · wolfssl · CWE-129 | Critical9.1 | — | 0.7% | Mar 25, 2024 |
36Monitor | CVE-2023-6936No exploit | Heap-buffer over-read with WOLFSSL_CALLBACKSwolfssl · wolfssl · CWE-125 | Critical9.1 | — | 0.6% | Feb 20, 2024 |
35Monitor | CVE-2023-3724No exploit | TLS 1.3 client issue handling malicious server when not including a KSE and PSK extensionwolfssl · wolfssl · CWE-20 | High8.8 | — | 0.7% | Jul 17, 2023 |
35Monitor | CVE-2024-1545No exploit | Fault Injection of RSA encryption in WolfCryptwolfssl · wolfssl · CWE-252 | High8.8 | — | 0.6% | Aug 29, 2024 |
35Monitor | CVE-2026-6679No exploit | DTLS 1.3 ACK serialization heap buffer overflow via integer truncationwolfssl · wolfssl · CWE-190 | High8.8 | — | 0.5% | Jun 25, 2026 |
35Monitor | CVE-2024-2881No exploit | Fault Injection of EdDSA signature in WolfCryptwolfssl · wolfssl · CWE-252 | High8.8 | — | 0.5% | Aug 29, 2024 |
34Monitor | CVE-2026-5500No exploit | Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypasswolfssl · wolfssl · CWE-20 | High8.7 | — | 0.4% | Apr 10, 2026 |
34Monitor | CVE-2026-11310No exploit | X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoringwolfssl · wolfssl · CWE-295 | High8.7 | — | 0.2% | Jun 25, 2026 |
34Monitor | CVE-2026-5501No exploit | Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificateswolfssl · wolfssl · CWE-295 | High8.6 | — | 0.2% | Apr 10, 2026 |
33Monitor | CVE-2026-5264No exploit | DTLS 1.3 ACK heap buffer overflowwolfssl · wolfssl · CWE-122 | High8.3 | — | 0.6% | Apr 9, 2026 |
- CVE-2009-448451Plan
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysq
HighCVSS 7.5WeaponizedEPSS 70%oracle · mysqlDec 30, 2009
- CVE-2019-1187342Plan
wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size.
CriticalCVSS 9.8No exploitEPSS 9%wolfssl · wolfsslMay 23, 2019
- CVE-2017-280042Plan
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif
CriticalCVSS 9.8Proof of conceptEPSS 9%wolfssl · wolfsslMay 24, 2017
- CVE-2020-3617740Plan
RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest s
CriticalCVSS 9.8No exploitEPSS 4%wolfssl · wolfsslJan 6, 2021
- CVE-2014-289640Plan
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified
CriticalCVSS 9.8No exploitEPSS 3%wolfssl · wolfsslJan 28, 2020
- CVE-2014-289740Plan
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows re
CriticalCVSS 9.8No exploitEPSS 3%wolfssl · wolfsslJan 28, 2020
- CVE-2014-289840Plan
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers
CriticalCVSS 9.8No exploitEPSS 3%wolfssl · wolfsslJan 28, 2020
- CVE-2019-643940Plan
examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.
CriticalCVSS 9.8No exploitEPSS 3%wolfssl · wolfsslJan 15, 2019
- CVE-2024-599140Plan
Buffer overread in domain name matching
CriticalCVSS 10.0No exploitEPSS 1%wolfssl · wolfsslAug 27, 2024
- CVE-2021-3715539Monitor
wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the seria
CriticalCVSS 9.8No exploitEPSS 1%wolfssl · wolfsslJul 21, 2021
- CVE-2019-1674839Monitor
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking.
CriticalCVSS 9.8No exploitEPSS 1%wolfssl · wolfsslSep 24, 2019
- CVE-2019-1565139Monitor
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte
CriticalCVSS 9.8No exploitEPSS 1%wolfssl · wolfsslAug 26, 2019
- CVE-2022-4290537Monitor
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network atta
CriticalCVSS 9.1No exploitEPSS 2%wolfssl · wolfsslNov 6, 2022
- CVE-2026-519437Monitor
wolfSSL ECDSA Certificate Verification
CriticalCVSS 9.3No exploitEPSS 0%wolfssl · wolfsslApr 9, 2026
- CVE-2022-2340836Monitor
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations.
CriticalCVSS 9.1No exploitEPSS 1%wolfssl · wolfsslJan 18, 2022
- CVE-2024-090136Monitor
SEGV and out of bounds memory read from malicious packet
CriticalCVSS 9.1No exploitEPSS 1%wolfssl · wolfsslMar 25, 2024
- CVE-2023-693636Monitor
Heap-buffer over-read with WOLFSSL_CALLBACKS
CriticalCVSS 9.1No exploitEPSS 1%wolfssl · wolfsslFeb 20, 2024
- CVE-2023-372435Monitor
TLS 1.3 client issue handling malicious server when not including a KSE and PSK extension
HighCVSS 8.8No exploitEPSS 1%wolfssl · wolfsslJul 17, 2023
- CVE-2024-154535Monitor
Fault Injection of RSA encryption in WolfCrypt
HighCVSS 8.8No exploitEPSS 1%wolfssl · wolfsslAug 29, 2024
- CVE-2026-667935Monitor
DTLS 1.3 ACK serialization heap buffer overflow via integer truncation
HighCVSS 8.8No exploitEPSS 1%wolfssl · wolfsslJun 25, 2026
- CVE-2024-288135Monitor
Fault Injection of EdDSA signature in WolfCrypt
HighCVSS 8.8No exploitEPSS 0%wolfssl · wolfsslAug 29, 2024
- CVE-2026-550034Monitor
Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass
HighCVSS 8.7No exploitEPSS 0%wolfssl · wolfsslApr 10, 2026
- CVE-2026-1131034Monitor
X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
HighCVSS 8.7No exploitEPSS 0%wolfssl · wolfsslJun 25, 2026
- CVE-2026-550134Monitor
Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates
HighCVSS 8.6No exploitEPSS 0%wolfssl · wolfsslApr 10, 2026
- CVE-2026-526433Monitor
DTLS 1.3 ACK heap buffer overflow
HighCVSS 8.3No exploitEPSS 1%wolfssl · wolfsslApr 9, 2026