wolfSSL wolfEngine

2 known vulnerabilities in wolfSSL wolfEngine, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-81341 CVSS 6.5 medium wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the…
  • CVE-2026-81020 CVSS 7.4 high wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record…