WireGuard is a modern VPN protocol and implementation that emphasizes cryptographic simplicity and performance in network tunneling, with a comparatively narrow codebase and product scope. Its reported vulnerabilities center on concurrency and resource-access patterns—race conditions under shared execution contexts and externally controlled references—characteristic of the synchronization demands inherent to a kernel-space or performance-critical networking component. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wireguard over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-35838MEDIUM The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. Th | Aug 9, 2023 | 5.7 | 20 | NO | NO |
CVE-2021-46873MEDIUM WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., bec | Jan 29, 2023 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wireguard.
Media articles that mention a CVE ID that affects a product developed by Wireguard — matched by CVE ID, not by vendor name.