wolfSSL.wolfssl is vulnerable to Insecure Randomness
70
High Risk
Affected versions of wolfssl are vulnerable to generating weak or predictable random values when applications call RAND_bytes() after fork() due to unexpected behavior in RAND_poll() within the OpenSSL compatibility layer. This issue can result in insufficiently reseeded randomness in child processes, potentially weakening security for applications that rely on RAND_bytes() post-fork, though internal TLS operations are not affected. Updating to a fixed version ensures the DRBG is properly reseeded after a fork.
You are affected if you are using a version that falls within the vulnerable range.
wolfSSL.wolfssl is vulnerable to Insecure Randomness in versions 3.15.0 - 5.8.0.
Upgrade the wolfSSL.wolfssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant