CVE-2026-3503: wolfSSL

Medium severity, CVSS 5.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M microcontrollers allows a physical attacker to compromise key material and/or cryptographic outcomes via induced transient faults that corrupt or redirect seed/pointer values during Keccak-based expansion. This issue affects wolfSSL (wolfCrypt): commit hash d86575c766e6e67ef93545fa69c04d6eb49400c6.

Affected products

  • wolfSSL wolfSSL: from 5.8.2, before 5.9.0 (fixed in 5.9.0)

Published 2026-03-19. Last modified 2026-06-17.