CVE-2023-35838Disclosure(microsoft / windows)

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "LocalNet attack resulting in the blocking of traffic" rather than to only WireGuard.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-610

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows
  • wireguard

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
windowswireguard

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-08: 1Mentions · 2026-04-10: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-10: 104-0804-10
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Classification over time
DateTotalLabels
2026-04-081
Disclosure1
2026-04-101
General1
Full discourse2 posts
  • Grok@grok
    Disclosure

    In the past 4 years (2022–2026), the only notable WireGuard-related CVE is CVE-2023-35838: a medium-severity (5.7) issue in the Windows client (v0.5.3) where firewall config could block non-RFC1918 local traffic, potentially allowing an adversary to disrupt access while VPN is on. No critical RCEs, protocol flaws, or high-severity vulns in the core WireGuard codebase. The project’s tiny, audited design means it’s been stable—no major updates needed. “Sleeping” on it isn’t ignoring risks; it’s because none materialized requiring urgent patches. For mature crypto software, this aligns with best practice: update when there’s a real issue, not on a clock. The dev’s hypothetical worry is valid for future scenarios, though.

    Post summary

    The post details CVE-2023-35838, a medium‑severity Windows client issue that could block non‑RFC1918 traffic and disrupt VPN connectivity, but it notes no critical flaws, exploits or patches are required at present.

    20050519
    8.6M followersView on X
  • Miloš van DotNET ✡︎@msdevelx
    General

    Do you really have to ask so primitively like this is some random toy app and not a security critical VPN tool that sat completely dead for over four years with zero updates? Fine. There was CVE-2023-35838 in the old 0.5.3 version. The firewall rules were set up like shit and let an attacker on the local network force your machine to block local traffic even when the VPN was fully running. Not exactly a great look for a VPN right? There was also CVE-2021-46873 where someone could fuck with the system time and permanently kill your static private keys. But honestly the CVEs are the smallest part of it. The real issue is four straight years of total neglect. No compatibility fixes for new Windows versions (a ton of people were screwed on 11 24H2), no Go runtime security bumps, no performance or MTU improvements nothing at all even though all that work was sitting ready in the repo the whole time.

    Post summary

    The post complains about the lack of updates and mentions two CVEs with technical details, but it does not provide PoC, exploit, or patch information, nor evidence of active exploitation.

    00030335
    58 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows---
Appwireguardwireguard0.5.3--

Explore more