Intel

AIKIDO-2025-10994

wolfSSL.wolfssl is vulnerable to Observable Discrepancy

Observable DiscrepancyCVE-2025-13912 Published Dec 29, 2025

10

Low Risk

This Affects:

C++wolfSSL.wolfssl
5.8.2 - 5.8.2
Fixed in 5.8.4
Are you affected? Scan for Free

TL;DR

Multiple constant-time implementations in wolfSSL prior to version 5.8.4 may be converted into non-constant-time binaries due to LLVM compiler optimizations. This can introduce observable timing differences, potentially leading to information disclosure via timing side-channel attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wolfSSL.wolfssl is vulnerable to Observable Discrepancy in versions 5.8.2 - 5.8.2.

How to fix this

Upgrade the wolfSSL.wolfssl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform