wolfSSL.wolfssl is vulnerable to Covert Timing Channel
56
Medium Risk
Affected versions of wolfssl include Curve25519 blinding support enabled by default in applicable builds, providing additional protection against potential side-channel attacks. While practical private-key extraction via side channels is considered difficult, blinding helps reduce the risk on devices that may be exposed to physical access or side-channel observation, improving overall cryptographic robustness.
You are affected if you are using a version that falls within the vulnerable range.
wolfSSL.wolfssl is vulnerable to Covert Timing Channel in versions 5.8.0 - 5.8.0.
Upgrade the wolfSSL.wolfssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant