Debian Wolfssl vulnerabilities
85 known vulnerabilities affecting debian/wolfssl.
Total CVEs
85
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH22MEDIUM35LOW18
Vulnerabilities
Page 5 of 5
CVE-2019-13628P4MEDIUMCVSS 4.7fixed in wolfssl 4.1.0+dfsg-1 (bookworm)2019
CVE-2019-13628 [MEDIUM] CVE-2019-13628: wolfssl - wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc,...
wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc, --enable-sp, or --enable-sp-math) contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to precisely measure the duration of signature operations, to infer information about the nonces used and potentially mount a lattice attack to recover the
debian
CVE-2025-11934P4LOWCVSS 2.1fixed in wolfssl 5.8.4-1 (forky)2025
CVE-2025-11934 [LOW] CVE-2025-11934: wolfssl - Improper input validation in the TLS 1.3 CertificateVerify signature algorithm n...
Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm used. For example when a client sends ECDSA P521 as the supported signature algorithm the server previously could respond as ECDSA P256 being the accepted signature algorithm and t
debian
CVE-2026-3230P4LOWCVSS 1.2fixed in wolfssl 5.9.0-0.1 (forky)2026
CVE-2026-3230 [LOW] CVE-2026-3230: wolfssl - Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest hand...
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared
debian
CVE-2026-4159P4LOWCVSS 1.2fixed in wolfssl 5.9.0-0.1 (forky)2026
CVE-2026-4159 [LOW] CVE-2026-4159: wolfssl - 1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted c...
1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_DecodeEnvelopedData could be triggered by a crafted CMS EnvelopedData message with zero-length encrypted content. Note that PKCS7 support is disabled by default.
Scope: local
boo
debian
CVE-2025-13912P4LOWCVSS 1.0fixed in wolfssl 5.8.4-1 (forky)2025
CVE-2025-13912 [LOW] CVE-2025-13912: wolfssl - Multiple constant-time implementations in wolfSSL before version 5.8.4 may be tr...
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.8.4-1)
sid: resolve
debian
← Previous5 / 5