wolfSSL released version 5.9.4 addressing 11 vulnerabilities in its embedded TLS and cryptography library: three high-severity, four medium-severity, and four low-severity issues. The most serious defects affect particular optional features and non-default configurations, including trusted-peer certificates, RFC 6961 multiple OCSP stapling, and Raw Public Key support; affected deployments could permit certificate-validation bypasses or certificate forgery. Other fixes cover X.509 name-constraint validation, revoked-certificate handling, TLS/DTLS 1.2 ChangeCipherSpec processing, session-cache state, certificate-signature verification, and a TLS shutdown use-after-free condition.
The Canadian Centre for Cyber Security issued advisory AV26-969 for wolfSSL versions 5.9.4 and earlier and directed administrators to review the vendor release and apply available updates. Organizations using wolfSSL 5.9.2 or earlier should upgrade to 5.9.4 or an equivalent downstream package, assess enabled compile-time options and exposed APIs, and restart long-running affected applications where certificate or session state may remain in memory. The release also adds post-quantum cryptography capabilities, including native Falcon, FrodoKEM, and SLH-DSA support and AVX512 acceleration for ML-KEM and ML-DSA.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-969 concerning vulnerabilities affecting wolfSSL. It identified versions 5.9.4 and earlier as affected and advised users and administrators to review the release information and apply necessary updates when available.
wolfSSL released version 5.9.4, which addresses 11 vulnerabilities in its embedded TLS and cryptography library. The fixes include certificate-validation and authentication bypasses, OCSP/CRL validation issues, session-cache confusion, and a TLS shutdown use-after-free; many affect optional build configurations or specific APIs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.