WolfSSL Product Security Update Advisory

WolfSSL Product Security Update Advisory

Overview

A security update has been released to address several vulnerabilities found in the wolfSSL product. Affected Versions are those prior to wolfSSL 5.9.1; Users should update to the latest version, wolfSSL 5.9.1 Or later.

Identified Vulnerabilities

The following CVEs are mentioned in the body of the announcement:

  • CVE-2026-5187.
  • CVE-2026-5188.
  • CVE-2026-5194.
  • CVE-2026-5263.
  • CVE-2026-5264.
  • CVE-2026-5295.
  • CVE-2026-5392.
  • CVE-2026-5393.
  • CVE-2026-5446.
  • CVE-2026-5447.
  • CVE-2026-5448.
  • CVE-2026-5460.
  • CVE-2026-5466.
  • CVE-2026-5477.
  • CVE-2026-5479.
  • CVE-2026-5500.
  • CVE-2026-5501.
  • CVE-2026-5503.
  • CVE-2026-5504.
  • CVE-2026-5507.
  • CVE-2026-5772.
  • CVE-2026-5778.
  • CVE-2026-6679.

Vulnerability Types

The report describes the following issues occurring in various components of wolfSSL:

  • Out-of-bounds write in the ASN.1 Object Identifier processing (CVE-2026-5187).
  • Integer underflow in the X.509 Subject Alternative Name processing (CVE-2026-5188).
  • Certificate forgery in the certificate signature verification process (CVE-2026-5194).
  • Certificate verification bypass due to insufficient validation of X.509 URI nameConstraints (CVE-2026-5263).
  • Heap buffer overflow in the DTLS 1.3 ACK message processing (CVE-2026-5264).
  • Stack buffer overflow during PKCS#7 Other Recipient Info OID processing (CVE-2026-5295).
  • Out-of-bounds read during PKCS#7 data processing (CVE-2026-5392).
  • Out-of-bounds read in the Dual-Algorithm CertificateVerify processing (CVE-2026-5393).
  • Nonce reuse in the TLS 1.2 ARIA-GCM encryption process (CVE-2026-5446).
  • Heap buffer overflow in the X.509 AuthorityKeyIdentifier processing (CVE-2026-5447).
  • Buffer overflow in the X.509 Certificate date processing (CVE-2026-5448).
  • Double-free in the TLS 1.3 PQC Hybrid KeyShare processing (CVE-2026-5460).
  • Signature forgery in the ECCSI signature verification process (CVE-2026-5466).
  • Authentication bypass in the AES-EAX and CMAC processing (CVE-2026-5477).
  • Authentication bypass in the ChaCha20-Poly1305 EVP decryption process (CVE-2026-5479).
  • Authentication bypass in the PKCS#7 AES-GCM authentication tag processing (CVE-2026-5500).
  • Certificate validation bypass in the OpenSSL-compatible X.509 Certificate validation process (CVE-2026-5501).
  • Heap buffer overflow in the TLS 1.3 ECH/SNI processing (CVE-2026-5503).
  • Padding oracle in the PKCS#7 CBC decryption process (CVE-2026-5504).
  • Incorrect memory deallocation in the session cache restoration process (CVE-2026-5507).
  • Out-of-bounds read in the domain name validation process (CVE-2026-5772).
  • Integer underflow and out-of-bounds read in the ChaCha20-Poly1305 decryption process (CVE-2026-5778).
  • Heap buffer overflow in the DTLS 1.3 ACK serialization process (CVE-2026-6679).

Mitigation

The report recommends updating to the latest version of the Vulnerability Patch to address these vulnerabilities, following the instructions provided on the reference site.