wolfSSL Inc.
First CVE: Jul 17, 2023Active for: 3 years
101
CVEs Published
More CVEs Published than 70% of tracked CNAs
25.3
Avg CVEs / Year
More Avg CVEs / Year than 74% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by wolfSSL Inc. as a CNA, 92.1% affect products that wolfSSL Inc. develops as a vendor.
92.1%
Self-reported: 93Third-party: 8
Of all the CVEs published that affect products developed by wolfSSL Inc., 61.6% are self-published by wolfSSL Inc. as a CNA.
61.6%
38.4%
Self-published: 93Published by other CNAs: 58
Trends Over Time
The number and severity of CVEs published by wolfSSL Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2023
3 years ago
Most Recent CVE
Jun 25, 2026
29 days ago
Top CVEs
All CVEs published by wolfSSL Inc. as a CNA, regardless of affected vendor or product.
101 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6094CRITICAL Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME | Jun 25, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-7531CRITICAL Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid | Jun 25, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-11310HIGH X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and who | Jun 25, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-55960HIGH Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so ParseCertRelative() accepts it with | Jun 25, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-5194CRITICAL Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accept | Apr 9, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-5187CRITICAL Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one available slot before writing two OID | Apr 9, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-6331HIGH HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path th | Jun 25, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-6679HIGH A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when com | Jun 25, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-55958HIGH Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fai | Jun 25, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-11999HIGH X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra | Jun 25, 2026 | 7.5 | 34 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA101 CVEs
39%
37%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (6.9%)
Network86 (85.1%)
Unknown0 (0.0%)
Physical3 (3.0%)
Adjacent Network5 (5.0%)
Attack Complexity
Low92 (91.1%)
High9 (8.9%)
Unknown0 (0.0%)
User Interaction
None96 (95.0%)
Unknown0 (0.0%)
Required4 (4.0%)
Privileges Required
Low20 (19.8%)
High6 (5.9%)
None75 (74.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (101 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by wolfSSL Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by wolfSSL Inc. as a CNA — matched by CVE ID, not by organization name.