1
/ 10
LOW
CVSS:4.0/AV:P/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N
Description
Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now turned on as the default for Xtensa.
Basic Information
ID
CVE-2025-12888
Source
wolfSSL
Published
Nov 21, 2025 at 22:50
Affected Product
Vendor
wolfSSL
Product
wolfSSL
Version
5.8.2
Affected Versions
wolfSSL wolfSSL 5.8.2