Critical Vulnerability in wolfSSL Affects 5 Billion Devices

Critical Vulnerability in wolfSSL Affects 5 Billion Devices

First seen 13 Apr 2026, 20:33 UTC CybernewsBleepingcomputergithub.comHeise.DeScworld+2 85% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-5194) in the wolfSSL library, which handles TLS encryption for over 5 billion devices, allows attackers to forge digital signatures, potentially compromising certificate-based authentication. The flaw arises from missing checks for hash/digest sizes and Object Identifiers (OIDs), enabling the acceptance of weak digests during signature verification. This vulnerability impacts multiple signature algorithms, including ECDSA, DSA, and EdDSA. An emergency patch was released in wolfSSL version 5.9.1 on April 8, 2026, to address this issue. Security experts warn that outdated devices may remain vulnerable as many manufacturers may not issue updates. The flaw has been rated as critical, with a severity score of 9.3 to 10.0, indicating a high risk of exploitation. Organizations using wolfSSL are urged to apply the patch immediately to mitigate risks.

Key Points: • CVE-2026-5194 allows forgery of digital signatures in wolfSSL, affecting 5 billion devices. • The vulnerability stems from inadequate checks on hash/digest sizes and OIDs during verification. • An emergency patch (version 5.9.1) was released on April 8, 2026, but many devices may remain unpatched.

ThreatCluster AI

Timeline

2024-02-09
CVE-2023-6935 published
2024-02-15
CVE-2023-6937 published
2024-02-20
CVE-2023-6936 published
2024-03-25
CVE-2024-0901 published
2024-08-27
CVE-2024-5814 published
2024-08-27
CVE-2024-5288 published
2024-08-27
CVE-2024-1544 published
2024-08-27
CVE-2024-5991 published
2024-08-29
CVE-2024-1545 published
2025-11-21
CVE-2025-12888 published

Community

Browse all →