CVE-2026-5446Disclosure(wolfssl / wolfssl)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every application-data record. Because wc_AriaEncrypt is stateless and passes the caller-supplied IV verbatim to the MagicCrypto SDK with no internal counter, and because the explicit IV is zero-initialized at session setup and never incremented in non-FIPS builds. This vulnerability affects wolfSSL builds configured with --enable-aria and the proprietary MagicCrypto SDK (a non-default, opt-in configuration required for Korean regulatory deployments). AES-GCM is not affected because wc_AesGcmEncrypt_ex maintains an internal invocation counter independently of the call-site guard.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-323

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-14: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-14: 104-0904-14
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-141
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5446 GCM Nonce Reuse Vulnerability in wolfSSL ARIA-GCM TLS 1.2 and DTLS 1.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5446

    Post summary

    The text announces the discovery of CVE-2026-5446, a GCM nonce reuse vulnerability in wolfSSL, without additional exploit or mitigation details.

    0000053
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5446 In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every application-data record. Because wc_AriaEncrypt is statel… https://www.cve.org/CVERecord?id=CVE-2026-5446 ----- Traducción: CVE-2026-5446 En … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑5446, describing a nonce reuse flaw in wolfSSL’s ARIA‑GCM cipher suites, but offers no PoC, exploit code, active exploitation, or patch information.

    0000031
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5446 In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every application-data record. Because wc_AriaEncrypt is statel… https://www.cve.org/CVERecord?id=CVE-2026-5446

    Post summary

    This brief statement announces CVE-2026-5446, detailing how wolfSSL’s ARIA‑GCM cipher suites reuse the same 12‑byte nonce for each record, indicating a potential security flaw, but it offers no PoC, exploit, or patch information.

    00000114
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more