CVE-2025-11936
published 2025-11-21CVE-2025-11936: Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.41%
33.1th percentile
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 5.8.4-1 (forky) | wolfssl 5.8.4-1 (forky) |
| msrc | azl3_mariadb_10.11.11-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_mariadb_10.6.21-1_on_cbl_mariner_2.0 | — | — |
| wolfssl | wolfssl | >= 0 < 5.8.4-1 | 5.8.4-1 |
| wolfssl | wolfssl | >= 3.12.0 < 5.8.4 | 5.8.4 |
| wolfssl | wolfssl | >= 5.8.2 < 5.8.4 | 5.8.4 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mmq-prpj-ww9q: Improper input validation in the TLS 1
ghsa_unreviewed·2025-11-22
CVE-2025-11936 [MEDIUM] CWE-20 GHSA-2mmq-prpj-ww9q: Improper input validation in the TLS 1
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.
OSV
CVE-2025-11936: Improper input validation in the TLS 1
osv·2025-11-21·CVSS 6.3
CVE-2025-11936 [MEDIUM] CVE-2025-11936: Improper input validation in the TLS 1
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.
Microsoft
Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello
vendor_msrc·2025-11-11·CVSS 5.3
CVE-2025-11936 [MEDIUM] CWE-20 Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello
Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello
Mariner: Mariner
wolfSSL: wolfSSL
Customer Action Required: Yes
Debian
CVE-2025-11936: wolfssl - Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2...
vendor_debian·2025·CVSS 6.3
CVE-2025-11936 [MEDIUM] CVE-2025-11936: wolfssl - Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2...
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.8.4-1)
sid: resolved (fixed in 5.8.4-1)
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-21
Published