OVERVIEW CVE-2026-5446 is a cryptographic nonce reuse vulnerability in wolfSSL's ARIA-GCM cipher suite implementation affecting TLS 1.2 and DTLS 1.2 connections. The vulnerability occurs because the wc_AriaEncrypt function fails to maintain an internal counter for GCM nonces, causing the same 12-byte nonce to be reused for every application-data record when the MagicCrypto SDK is enabled. This flaw impacts only non-default wolfSSL builds compiled with the --enable-aria flag and the proprietary MagicCrypto SDK, a configuration primarily required for Korean regulatory compliance. AES-GCM cipher suites are not affected due to their independent invocation counter mechanism. SEVERITY The vulnerability presents a network-based attack vector with low complexity, as exploitation requires only establishing a TLS/DTLS session using affected ARIA-GCM cipher suites. Nonce reuse in GCM mode fundamentally undermines the authenticated encryption guarantee, potentially allowing attackers to forge ciphertexts and decrypt previously captured encrypted records. However, the impact is significantly constrained by the opt-in, non-default configuration requirement and limited adoption of ARIA cipher suites outside specific regulatory jurisdictions. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. No public exploit code is documented, and the vulnerability received minimal community attention, as indicated by its inactive status on the CISA Known Exploited Vulnerabilities catalog. The extremely low EPSS score of 0.0005 reflects the limited attack surface posed by this configuration-specific vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.2.1, < 5.9.1CPE match | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.