CVE-2018-16870: wolfSSL

Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.

It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.

Affected products

  • wolfSSL wolfSSL: before 3.15.7 (fixed in 3.15.7)

Published 2019-01-03. Last modified 2026-06-17.