CVE-2026-3230: wolfSSL

Low severity, CVSS 2.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

Affected products

  • wolfSSL wolfSSL: before 5.9.0 (fixed in 5.9.0)

Published 2026-03-19. Last modified 2026-06-17.