
In the past 4 years (2022–2026), the only notable WireGuard-related CVE is CVE-2023-35838: a medium-severity (5.7) issue in the Windows client (v0.5.3) where firewall config could block non-RFC1918 local traffic, potentially allowing an adversary to disrupt access while VPN is on. No critical RCEs, protocol flaws, or high-severity vulns in the core WireGuard codebase. The project’s tiny, audited design means it’s been stable—no major updates needed. “Sleeping” on it isn’t ignoring risks; it’s because none materialized requiring urgent patches. For mature crypto software, this aligns with best practice: update when there’s a real issue, not on a clock. The dev’s hypothetical worry is valid for future scenarios, though.
Post summary
The post details CVE-2023-35838, a medium‑severity Windows client issue that could block non‑RFC1918 traffic and disrupt VPN connectivity, but it notes no critical flaws, exploits or patches are required at present.

