wolfssl

3 records · 3 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names wolfssl as an affected vendor, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-89102public PoC

    In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feat…

    wolfssl

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.4CVE-2026-94419public PoC

    Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() validates it against that hash alone…

    wolfssl

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-94417public PoC

    When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that carries no Authority Information Access OCSP URL, and accepts a certificate the loaded CRL li…

    wolfssl

    AI risk analysis on Exploit-DB.ai →