CVE-2026-3230
published 2026-03-19CVE-2026-3230: Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of…
PriorityP412low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.21%
11.1th percentile
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 5.9.0-0.1 (forky) | wolfssl 5.9.0-0.1 (forky) |
| msrc | azl3_mariadb_10.11.16-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_mariadb_10.6.24-1_on_cbl_mariner_2.0 | — | — |
| wolfssl | wolfssl | < 5.9.0 | 5.9.0 |
| wolfssl | wolfssl | >= 0 < 5.9.0-0.1 | 5.9.0-0.1 |
CVSS provenance
nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
nvdv4.01.2LOWCVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:D/RE:X/U:Clear
osv1.2LOW
vendor_debian1.2LOW
vendor_msrc1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g3xr-5f55-cf5g: Missing required cryptographic step in the TLS 1
ghsa_unreviewed·2026-03-19
CVE-2026-3230 [LOW] CWE-20 GHSA-g3xr-5f55-cf5g: Missing required cryptographic step in the TLS 1
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.
OSV
CVE-2026-3230: Missing required cryptographic step in the TLS 1
osv·2026-03-19·CVSS 1.2
CVE-2026-3230 [LOW] CVE-2026-3230: Missing required cryptographic step in the TLS 1
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.
Microsoft
Improper key_share validation in TLS 1.3 HelloRetryRequest
vendor_msrc·2026-03-10·CVSS 1.2
CVE-2026-3230 [LOW] CWE-20 Improper key_share validation in TLS 1.3 HelloRetryRequest
Improper key_share validation in TLS 1.3 HelloRetryRequest
Mariner: Mariner
wolfSSL: wolfSSL
Customer Action Required: Yes
Debian
CVE-2026-3230: wolfssl - Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest hand...
vendor_debian·2026·CVSS 1.2
CVE-2026-3230 [LOW] CVE-2026-3230: wolfssl - Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest hand...
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.9.0-0.1)
sid: resolved (fixed in 5.9.0-0.1)
trixie: open
No detection rules found.
No public exploits indexed.
abuse.ch
ThreatFox Malware Profile: Unidentified 001
abuse_ch·2026-04-03
CVE-2026-21513 ThreatFox Malware Profile: Unidentified 001
Malware Family: Unidentified 001
Internal name: win.unidentified_001
ThreatFox has tracked 10 indicators of compromise for this malware family.
Activity observed from 2026-03-30 to 2026-04-03.
Threat categories: botnet command-and-control server (6 IOCs); malicious payload (4 IOCs)
Indicator types: IP address and port (4); SHA-256 file hash (4); domain name (2)
Associated tags: c2 (2), None (2), staging (1), cpl (1), mitm (1), cve-2026-21513 (1), cve-2011-3230 (1), cloudflare (1)
Wiz
CVE-2026-3230 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 1.2
CVE-2026-3230 [LOW] CVE-2026-3230 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3230 :
wolfSSL vulnerability analysis and mitigation
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.
Source : NVD
## 1.2
Score
Published March 19, 2026
Severity LOW
CNA Score 1.2
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19
2026-03-19
Published