Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/wolfssl/wolfssl

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

This vulnerability involves a bypass of IP address name constraints in WOLFSSL when the WOLFSSL_IP_ALT_NAME configuration is not defined. In this configuration, IP address constraints specified by the issuing Certificate Authority (CA) are not enforced, allowing certificates to bypass these restrictions. No specific affected versions are stated. There is no known exploit in the wild, and no patch or official remediation has been indicated.

Join the discussion

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

Join the discussion

A heap buffer overflow vulnerability exists in the DTLS 1.3 ACK serialization path of wolfSSL versions 5.9.0 and earlier. The flaw is caused by an integer truncation error that leads to allocation of an undersized buffer, which is then overrun. This vulnerability was fixed in wolfSSL version 5.9.1.

Join the discussion

This vulnerability involves certificates with wildcard DNS Subject Alternative Names (SANs) bypassing Certificate Authority (CA) name-constraint checks. Specifically, a certificate containing a wildcard DNS SAN (e.g., *.example.com) that should be rejected due to the issuing CA's permitted or excluded DNS name constraints may be incorrectly accepted. This issue relates to improper enforcement of name constraints in certificate validation.

Join the discussion

An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when certificate data was written out of bounds of an insufficiently sized certificate buffer.wolfssl_add_to_chain is called by these API: wolfSSL_CTX_add_extra_chain_cert, wolfSSL_CTX_add1_chain_cert, wolfSSL_add0_chain_cert. These API are enabled for 3rd party compatibility features: enable-opensslall, enable-opensslextra, enable-lighty, enable-stunnel, enable-nginx, enable-haproxy. This issue is not remotely exploitable, and would require that the application context loading certificates is compromised.

Join the discussion

Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciously crafted ECH config could cause a stack buffer overflow on the client side, leading to potential remote execution and client program crash. This could be exploited by a malicious TLS server supporting ECH. Note that ECH is off by default, and is only enabled with enable-ech.

Join the discussion

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

Join the discussion

CVE-2026-3503 is a medium severity vulnerability in wolfSSL's wolfCrypt library version 5.8.2 affecting ARM Cortex-M microcontrollers. The flaw involves incorrect usage of seeds in the pseudo-random number generator (PRNG) within post-quantum cryptographic implementations (ML-KEM and ML-DSA). Physical attackers can induce transient faults to corrupt or redirect seed or pointer values during the Keccak-based expansion process, potentially compromising key material or cryptographic outcomes. Exploitation requires physical access and high attack complexity, with no user interaction needed. This vulnerability impacts confidentiality due to possible key leakage but has limited scope and availability impact. No known exploits are reported in the wild. Organizations using affected wolfSSL versions on ARM Cortex-M devices should prioritize patching or apply hardware-level protections against fault injection attacks.

Join the discussion

Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/wolfssl/wolfssl
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses