Aller au contenu

Fiche vulnérabilité

CVE-2025-11936 : faille moyenne wolfssl wolfssl (CVSS 5.3)

Description

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.

En bref

Sévérité
Moyenne (CVSS 5.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitation active
Non signalée par la CISA
Publication
21 nov. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • wolfssl wolfssl

Références

Rechercher une autre vulnérabilité dans la base CVE