Intel

AIKIDO-2025-10976

wolfSSL.wolfssl is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2025-11933 Published Dec 24, 2025

23

Low Risk

This Affects:

C++wolfSSL.wolfssl
5.8.2 - 5.8.3
Fixed in 5.8.4
Are you affected? Scan for Free

TL;DR

Affected versions of wolfssl are vulnerable to a denial-of-service due to improper input validation when parsing the TLS 1.3 CKS extension. A remote unauthenticated attacker can trigger the issue by sending a crafted ClientHello message containing duplicate CKS extensions, potentially causing the service to become unavailable.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wolfSSL.wolfssl is vulnerable to Improper Input Validation in versions 5.8.2 - 5.8.3.

How to fix this

Upgrade the wolfSSL.wolfssl library to the patch version.