CVE-2026-3230: wolfSSL
Low severity, CVSS 2.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.
Affected products
- wolfSSL wolfSSL: before 5.9.0 (fixed in 5.9.0)
Published 2026-03-19. Last modified 2026-06-17.