WolfSSL Product Security Update Advisory
Overview
A security update has been released to address several vulnerabilities found in the wolfSSL product. Affected Versions are those prior to wolfSSL 5.9.1; Users should update to the latest version, wolfSSL 5.9.1 Or later.
Identified Vulnerabilities
The following CVEs are mentioned in the body of the announcement:
- CVE-2026-5187.
- CVE-2026-5188.
- CVE-2026-5194.
- CVE-2026-5263.
- CVE-2026-5264.
- CVE-2026-5295.
- CVE-2026-5392.
- CVE-2026-5393.
- CVE-2026-5446.
- CVE-2026-5447.
- CVE-2026-5448.
- CVE-2026-5460.
- CVE-2026-5466.
- CVE-2026-5477.
- CVE-2026-5479.
- CVE-2026-5500.
- CVE-2026-5501.
- CVE-2026-5503.
- CVE-2026-5504.
- CVE-2026-5507.
- CVE-2026-5772.
- CVE-2026-5778.
- CVE-2026-6679.
Vulnerability Types
The report describes the following issues occurring in various components of wolfSSL:
- Out-of-bounds write in the ASN.1 Object Identifier processing (CVE-2026-5187).
- Integer underflow in the X.509 Subject Alternative Name processing (CVE-2026-5188).
- Certificate forgery in the certificate signature verification process (CVE-2026-5194).
- Certificate verification bypass due to insufficient validation of X.509 URI nameConstraints (CVE-2026-5263).
- Heap buffer overflow in the DTLS 1.3 ACK message processing (CVE-2026-5264).
- Stack buffer overflow during PKCS#7 Other Recipient Info OID processing (CVE-2026-5295).
- Out-of-bounds read during PKCS#7 data processing (CVE-2026-5392).
- Out-of-bounds read in the Dual-Algorithm CertificateVerify processing (CVE-2026-5393).
- Nonce reuse in the TLS 1.2 ARIA-GCM encryption process (CVE-2026-5446).
- Heap buffer overflow in the X.509 AuthorityKeyIdentifier processing (CVE-2026-5447).
- Buffer overflow in the X.509 Certificate date processing (CVE-2026-5448).
- Double-free in the TLS 1.3 PQC Hybrid KeyShare processing (CVE-2026-5460).
- Signature forgery in the ECCSI signature verification process (CVE-2026-5466).
- Authentication bypass in the AES-EAX and CMAC processing (CVE-2026-5477).
- Authentication bypass in the ChaCha20-Poly1305 EVP decryption process (CVE-2026-5479).
- Authentication bypass in the PKCS#7 AES-GCM authentication tag processing (CVE-2026-5500).
- Certificate validation bypass in the OpenSSL-compatible X.509 Certificate validation process (CVE-2026-5501).
- Heap buffer overflow in the TLS 1.3 ECH/SNI processing (CVE-2026-5503).
- Padding oracle in the PKCS#7 CBC decryption process (CVE-2026-5504).
- Incorrect memory deallocation in the session cache restoration process (CVE-2026-5507).
- Out-of-bounds read in the domain name validation process (CVE-2026-5772).
- Integer underflow and out-of-bounds read in the ChaCha20-Poly1305 decryption process (CVE-2026-5778).
- Heap buffer overflow in the DTLS 1.3 ACK serialization process (CVE-2026-6679).
Mitigation
The report recommends updating to the latest version of the Vulnerability Patch to address these vulnerabilities, following the instructions provided on the reference site.