CVE-2025-11935

Name
CVE-2025-11935
Description
With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when a server responded to a ClientHello containing psk_dhe_ke without a key_share extension. The re-use of an authenticated PSK connection that on the clients side unexpectedly did not have PFS, reduces the security of the connection.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
facts@wolfssl.com https://github.com/wolfSSL/wolfssl
facts@wolfssl.com https://github.com/wolfSSL/wolfssl/pull/9112

Match rules

CPE URI Source package Min version Max version
wolfssl == v5.8.2 == None
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* wolfssl >= 5.8.2 < 5.8.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wolfssl edge-community 5.8.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.6-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.4-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.6.6-r0 None possibly vulnerable
wolfssl edge-community 5.6.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.5.3-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.5.1-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.5.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.4.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl 3.22-community 5.7.6-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl 3.22-community 5.7.4-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl 3.22-community 5.7.2-r0 None possibly vulnerable
wolfssl 3.22-community 5.7.0-r0 None possibly vulnerable
wolfssl 3.22-community 5.6.6-r0 None possibly vulnerable
wolfssl 3.22-community 5.6.2-r0 None possibly vulnerable
wolfssl 3.22-community 5.5.3-r0 None possibly vulnerable
wolfssl 3.22-community 5.5.1-r0 None possibly vulnerable
wolfssl 3.22-community 5.5.0-r0 None possibly vulnerable
wolfssl 3.22-community 5.4.0-r0 None possibly vulnerable