Critical wolfSSL Flaw Could Allow Attackers to Spoof Trusted Hosts
ID: fee616df-218b-54f0-a6a7-0d910444922c
STIX ID: report--fee616df-218b-54f0-a6a7-0d910444922c
Feed Name: securityonline.info
Threat Score
A critical vulnerability (CVE-2026-5194, CVSS 9.3) in the wolfSSL TLS library allows certificate validation bypass because ECDSA verification does not enforce hash/digest size and OID checks when used with EdDSA or ML-DSA, potentially enabling attackers to impersonate hosts, spoof data, and gain unauthorized privileges; developers should audit and update affected wolfSSL deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
