Intel

AIKIDO-2025-10987

wolfSSL.wolfssl is vulnerable to Inadequate Encryption Strength

Inadequate Encryption StrengthCVE-2025-11935 Published Dec 29, 2025

63

Medium Risk

This Affects:

C++wolfSSL.wolfssl
5.8.2 - 5.8.2
Fixed in 5.8.4
Are you affected? Scan for Free

TL;DR

With TLS 1.3 pre-shared keys (PSK), a malicious or faulty server could ignore the client’s request for perfect forward secrecy (PFS) and still establish a PSK connection without PFS. This occurs when the server responds to a ClientHello containing psk_dhe_ke without including a key_share extension. As a result, the client may unknowingly reuse an authenticated PSK connection without PFS, reducing the overall security of the connection.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wolfSSL.wolfssl is vulnerable to Inadequate Encryption Strength in versions 5.8.2 - 5.8.2.

How to fix this

Upgrade the wolfSSL.wolfssl library to the patch version.