wolfSSL.wolfssl is vulnerable to Improper Input Validation
21
Low Risk
Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier allows a signature algorithm downgrade on multiple platforms. A malicious server can select a weaker algorithm than the one proposed by the client, for example responding with ECDSA P256 when the client offered ECDSA P521, and the connection continues using the downgraded algorithm if the client supports it.
You are affected if you are using a version that falls within the vulnerable range.
wolfSSL.wolfssl is vulnerable to Improper Input Validation in versions 5.8.2 - 5.8.2.
Upgrade the wolfSSL.wolfssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant