CVE-2026-55967 Details
Description
AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent plaintext recovery.
A vulnerability exists in the wolfSSL library's streaming APIs for AES-GCM encryption and decryption. When single message sizes exceed 64 GiB, the APIs fail to properly reject these large messages, leading to counter wrap, keystream reuse, and the potential recovery of plaintext. This issue affects all versions of wolfSSL that are prior to the latest release.
Users are advised to update to the latest version of wolfSSL, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/wolfSSL/wolfssl/pull/10709 | [email protected] | Issue TrackingPatch |
| https://www.wolfssl.com/docs/security-vulnerabilities/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-323 | Reusing a Nonce, Key Pair in Encryption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wolfssl wolfssl | >= 4.8.0, < 5.9.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |