Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6 CVE-2026-6731

X.509 name constraint bypass via Subject CN treated as a DNS name_CVE-2026-6731

X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's D...

wolfSSL wolfSSL 3.9.10 CVE
MEDIUM 5.9 CVE-2026-8720

HMAC-BLAKE2 final discards message when key length exceeds block size_CVE-2026-8720

wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of ...

wolfSSL wolfSSL 5.9.0 CVE
MEDIUM 6.3 CVE-2026-6330

ML-KEM ARM64 NEON ciphertext comparison only compares half of the input_CVE-2026-6330

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weake...

wolfSSL wolfSSL 5.7.4 CVE
MEDIUM 6 CVE-2026-6329

PKCS#12 MAC verification uses attacker-controlled comparison length_CVE-2026-6329

PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to b...

wolfSSL wolfSSL 3.10.0 CVE
MEDIUM 6 CVE-2026-55962

TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify_CVE-2026-55962

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certific...

wolfSSL wolfSSL 5.5.4 CVE
MEDIUM 6.5 CVE-2026-44622

EVoke Systems EVoke CSMS Insufficiently Protected Credentials_CVE-2026-44622

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

EVoke EVoke CSMS All versions CVE
MEDIUM 6 CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption_CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A c...

wolfSSL wolfSSL 3.15.0 CVE
MEDIUM 6.3 CVE-2026-10098

OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status_CVE-2026-10098

OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the tar...

wolfSSL wolfSSL 4.6.0 CVE
MEDIUM 5.7 CVE-2026-7532

iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined_CVE-2026-7532

iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allo...

wolfSSL wolfSSL CVE
MEDIUM 5.9 CVE-2026-7511

PKCS7_verify signer confusion allows forged signatures to be accepted_CVE-2026-7511

PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged si...

wolfSSL wolfSSL 3.15.5 CVE