Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

wolfSSL Inc.

First CVE: Dec 30, 2009Active for: 17 yearsTotal CVEs: 151
45.2
VTI Score
High

wolfSSL Inc. maintains cryptographic and TLS libraries widely embedded in embedded systems, IoT devices, and resource-constrained applications, giving its products outsized impact despite a narrow portfolio. Despite the focused product line—centered on wolfSSL itself, wolfMQTT, and yaSSL—the vendor ranks among the most prominent in the vulnerability landscape because cryptographic libraries occupy a critical position in the software supply chain and reach countless downstream deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes including out-of-bounds writes and reads, heap-based buffer overflows, and improper certificate validation that reflect the low-level parsing and cryptographic-protocol demands of TLS implementations. Defenders should prioritize inventory of products embedding these libraries, as remediation often depends on downstream vendors rebuilding and releasing patches; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
151
Total CVEs
More Total CVEs than 99% of tracked vendors
4.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by wolfSSL Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2009
16 years ago
Most Recent CVE
Jun 25, 2026
29 days ago

Self-Reporting Analysis

Of all the CVEs published by wolfSSL Inc. as a CNA, 92.1% affect products that wolfSSL Inc. develops as a vendor.

92.1%
Self-reported: 93 (92.1%)
Third-party: 8 (7.9%)

Of all the CVEs published that affect products developed by wolfSSL Inc., 61.6% are self-published by wolfSSL Inc. as a CNA.

61.6%
38.4%
Self-published: 93 (61.6%)
Other CNAs: 58 (38.4%)

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (151 CVEs).

151 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-4484HIGH
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5
Dec 30, 20097.579NOYES
CVE-2017-2800CRITICAL
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial
May 24, 20179.846NOYES
CVE-2017-13099MEDIUM
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a
Dec 13, 20175.944NOYES
CVE-2026-6094CRITICAL
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME
Jun 25, 20269.138NONO
CVE-2026-7531CRITICAL
Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid
Jun 25, 20269.836NONO
CVE-2026-11310HIGH
X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and who
Jun 25, 20267.536NONO
CVE-2026-55960HIGH
Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so ParseCertRelative() accepts it with
Jun 25, 20267.536NONO
CVE-2026-5194CRITICAL
Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accept
Apr 9, 20269.136NONO
CVE-2026-5187CRITICAL
Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one available slot before writing two OID
Apr 9, 20269.835NONO
CVE-2019-11873CRITICAL
wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sends a crafted hello client pack
May 23, 20199.835NONO
View all 151 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products151 CVEs
44%
35%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local22 (14.6%)
Network121 (80.1%)
Unknown1 (0.7%)
Physical2 (1.3%)
Adjacent Network5 (3.3%)
Attack Complexity
Low130 (86.1%)
High20 (13.2%)
Unknown1 (0.7%)
User Interaction
None136 (90.1%)
Unknown1 (0.7%)
Required13 (8.6%)
Privileges Required
Low26 (17.2%)
High7 (4.6%)
None117 (77.5%)
Unknown1 (0.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (151 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by wolfSSL Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by wolfSSL Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For wolfSSL Inc.'s Products

View all 5 CNAs →

Top CWEs