Intel

AIKIDO-2025-10990

wolfSSL.wolfssl is vulnerable to Observable Discrepancy

Observable DiscrepancyCVE-2025-12888 Published Dec 29, 2025

10

Low Risk

This Affects:

C++wolfSSL.wolfssl
5.8.2 - 5.8.2
Fixed in 5.8.4
Are you affected? Scan for Free

TL;DR

A vulnerability exists in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, particularly on Xtensa-based ESP32 chips. When targeting Xtensa, it is recommended to use the low-memory X25519 implementations, which are now enabled by default for this architecture.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wolfSSL.wolfssl is vulnerable to Observable Discrepancy in versions 5.8.2 - 5.8.2.

How to fix this

Upgrade the wolfSSL.wolfssl library to the patch version.