CVE-2025-11936
MEDIUMWolfssl < 5.8.4 - Improper Input Validation
Title source: ruleDescription
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.
Scores
CVSS v3
5.3
EPSS
0.0004
EPSS Percentile
12.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-20
Status
published
Products (1)
wolfssl/wolfssl
5.8.2 - 5.8.4
Published
Nov 21, 2025
Tracked Since
Feb 18, 2026