CVE-2025-11935
published 2025-11-21CVE-2025-11935: With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.22%
12.0th percentile
With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 5.8.4-1 (forky) | wolfssl 5.8.4-1 (forky) |
| msrc | azl3_mariadb_10.11.11-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_mariadb_10.6.21-1_on_cbl_mariner_2.0 | — | — |
| wolfssl | wolfssl | >= 0 < 5.8.4-1 | 5.8.4-1 |
| wolfssl | wolfssl | >= 3.12.0 < 5.8.4 | 5.8.4 |
| wolfssl | wolfssl | >= 5.8.2 < 5.8.4 | 5.8.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.3MEDIUM
vendor_msrc7.5HIGH
vendor_debian6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Forward Secrecy Violation in WolfSSL TLS 1.3
vendor_msrc·2025-11-11·CVSS 7.5
CVE-2025-11935 [MEDIUM] CWE-326 Forward Secrecy Violation in WolfSSL TLS 1.3
Forward Secrecy Violation in WolfSSL TLS 1.3
Mariner: Mariner
wolfSSL: wolfSSL
Customer Action Required: Yes
Debian
CVE-2025-11935: wolfssl - With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the ...
vendor_debian·2025·CVSS 6.3
CVE-2025-11935 [MEDIUM] CVE-2025-11935: wolfssl - With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the ...
With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.8.4-1)
sid: resolved (fixed in 5.8.4-1)
trixie: open
GHSA
GHSA-4497-xvm3-5vh9: With TLS 1
ghsa_unreviewed·2025-11-22
CVE-2025-11935 [MEDIUM] CWE-326 GHSA-4497-xvm3-5vh9: With TLS 1
With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.
OSV
CVE-2025-11935: With TLS 1
osv·2025-11-21·CVSS 6.3
CVE-2025-11935 [MEDIUM] CVE-2025-11935: With TLS 1
With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-21
Published