Intel

AIKIDO-2025-10986

wolfSSL.wolfssl is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2025-11934 Published Dec 29, 2025

21

Low Risk

This Affects:

C++wolfSSL.wolfssl
5.8.2 - 5.8.2
Fixed in 5.8.4
Are you affected? Scan for Free

TL;DR

Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier allows a signature algorithm downgrade on multiple platforms. A malicious server can select a weaker algorithm than the one proposed by the client, for example responding with ECDSA P256 when the client offered ECDSA P521, and the connection continues using the downgraded algorithm if the client supports it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wolfSSL.wolfssl is vulnerable to Improper Input Validation in versions 5.8.2 - 5.8.2.

How to fix this

Upgrade the wolfSSL.wolfssl library to the patch version.