wolfssl
3 records · 3 with a public proof-of-concept
Disclosed vulnerabilities where the NVD names wolfssl as an affected vendor, highest CVSS first.
- MEDIUM 6.5CVE-2026-89102public PoC
In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feat…
wolfssl
- MEDIUM 5.4CVE-2026-94419public PoC
Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() validates it against that hash alone…
wolfssl
- MEDIUM 5.3CVE-2026-94417public PoC
When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that carries no Authority Information Access OCSP URL, and accepts a certificate the loaded CRL li…
wolfssl