CVE-2025-11936

Name
CVE-2025-11936
Description
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
facts@wolfssl.com https://github.com/wolfSSL/wolfssl
facts@wolfssl.com https://github.com/wolfSSL/wolfssl/pull/9117

Match rules

CPE URI Source package Min version Max version
wolfssl == v5.8.2 == None
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* wolfssl >= 5.8.2 < 5.8.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wolfssl edge-community 5.8.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.6-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.4-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.6.6-r0 None possibly vulnerable
wolfssl edge-community 5.6.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.5.3-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.5.1-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.5.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.4.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl 3.22-community 5.7.6-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl 3.22-community 5.7.4-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl 3.22-community 5.7.2-r0 None possibly vulnerable
wolfssl 3.22-community 5.7.0-r0 None possibly vulnerable
wolfssl 3.22-community 5.6.6-r0 None possibly vulnerable
wolfssl 3.22-community 5.6.2-r0 None possibly vulnerable
wolfssl 3.22-community 5.5.3-r0 None possibly vulnerable
wolfssl 3.22-community 5.5.1-r0 None possibly vulnerable
wolfssl 3.22-community 5.5.0-r0 None possibly vulnerable
wolfssl 3.22-community 5.4.0-r0 None possibly vulnerable