CVE-2026-3230

LOW

Improper key_share validation in TLS 1.3 HelloRetryRequest

Title source: cna

Description

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

Scores

CVSS v3 2.7
EPSS 0.0007
EPSS Percentile 21.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-20
Status published
Products (2)
wolfSSL/wolfSSL < 5.9.0
wolfssl/wolfssl < 5.9.0
Published Mar 19, 2026
Tracked Since Mar 20, 2026