logo

Critical wolfSSL Flaw Could Allow Attackers to Spoof Trusted Hosts

ID: fee616df-218b-54f0-a6a7-0d910444922c

STIX ID: report--fee616df-218b-54f0-a6a7-0d910444922c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-5194, CVSS 9.3) in the wolfSSL TLS library allows certificate validation bypass because ECDSA verification does not enforce hash/digest size and OID checks when used with EdDSA or ML-DSA, potentially enabling attackers to impersonate hosts, spoof data, and gain unauthorized privileges; developers should audit and update affected wolfSSL deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.