CVE-2025-13912: wolfSSL

Low severity, CVSS 1.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.

Affected products

  • wolfSSL wolfSSL: before 5.8.4 (fixed in 5.8.4)

Published 2025-12-11. Last modified 2026-06-17.