Intel

AIKIDO-2025-10989

wolfSSL.wolfssl is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2025-11936 Published Dec 29, 2025

63

Medium Risk

This Affects:

C++wolfSSL.wolfssl
5.8.2 - 5.8.2
Fixed in 5.8.4
Are you affected? Scan for Free

TL;DR

Improper input validation in TLS 1.3 KeyShareEntry parsing in wolfSSL 5.8.2 allows a remote, unauthenticated attacker on multiple platforms to trigger a denial of service. By sending a crafted ClientHello containing duplicate KeyShareEntry values for the same supported group, an attacker can cause excessive CPU usage and memory consumption during ClientHello processing.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wolfSSL.wolfssl is vulnerable to Improper Input Validation in versions 5.8.2 - 5.8.2.

How to fix this

Upgrade the wolfSSL.wolfssl library to the patch version.