CVE-2025-11933
published 2025-11-21CVE-2025-11933: Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.40%
32.5th percentile
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 5.8.4-1 (forky) | wolfssl 5.8.4-1 (forky) |
| msrc | azl3_mariadb_10.11.11-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_mariadb_10.6.21-1_on_cbl_mariner_2.0 | — | — |
| wofssl | wolfssl | >= 3.12.0 < 5.8.4 | 5.8.4 |
| wolfssl | wolfssl | >= 0 < 5.8.4-1 | 5.8.4-1 |
| wolfssl | wolfssl | >= 5.8.2 < 5.8.4 | 5.8.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv2.3LOW
vendor_msrc6.5MEDIUM
vendor_debian2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g9wx-2hxf-f2rj: Improper Input Validation in the TLS 1
ghsa_unreviewed·2025-11-22
CVE-2025-11933 [LOW] CWE-20 GHSA-g9wx-2hxf-f2rj: Improper Input Validation in the TLS 1
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions.
OSV
CVE-2025-11933: Improper Input Validation in the TLS 1
osv·2025-11-21·CVSS 2.3
CVE-2025-11933 [LOW] CVE-2025-11933: Improper Input Validation in the TLS 1
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions.
Microsoft
DoS Vulnerability in wolfSSL TLS 1.3 CKS Extension
vendor_msrc·2025-11-11·CVSS 6.5
CVE-2025-11933 [LOW] CWE-20 DoS Vulnerability in wolfSSL TLS 1.3 CKS Extension
DoS Vulnerability in wolfSSL TLS 1.3 CKS Extension
Mariner: Mariner
wolfSSL: wolfSSL
Customer Action Required: Yes
Debian
CVE-2025-11933: wolfssl - Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 ...
vendor_debian·2025·CVSS 2.3
CVE-2025-11933 [LOW] CVE-2025-11933: wolfssl - Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 ...
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.8.4-1)
sid: resolved (fixed in 5.8.4-1)
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-21
Published