Search CVE reports


Toggle filters

101 – 110 of 42193 results

Status is adjusted based on your filters.


CVE-2026-8720

Medium priority
Needs evaluation

wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the supplied key is longer than the BLAKE2 block size...

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-7532

Medium priority
Needs evaluation

iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-7511

Medium priority
Needs evaluation

PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-6331

Medium priority
Needs evaluation

HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path the supplied signature length was only checked as...

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-6330

Medium priority
Needs evaluation

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code path. The constant-time comparison effectively...

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-6329

Medium priority
Needs evaluation

PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the locally computed HMAC against the...

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-6325

Medium priority
Needs evaluation

Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-6092

Medium priority
Needs evaluation

When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-55962

Medium priority
Needs evaluation

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth exemption that allows an...

1 affected package

wolfssl

Package 20.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-22879

Medium priority
Needs evaluation

vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

1 affected package

vtk-dicom

Package 20.04 LTS
vtk-dicom Needs evaluation
Show less packages