CVE-2026-6330Disclosure(wolfssl / wolfssl)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code path. The constant-time comparison effectively ignored part of the re-encrypted ciphertext, so a decapsulating party could fail to detect a manipulated ciphertext and proceed without the standard's required implicit rejection.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-25); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-25: 2Mentions · 2026-07-02: 2Technical Details · 2026-06-25: 206-2507-02
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-252
Disclosure2
2026-07-022
General2
Full discourse4 posts
  • Daniel J. Bernstein@hashbreaker
    General

    Wasn't someone saying a moment ago that ML-KEM is super-easy to implement correctly? How do we explain https://www.cve.org/CVERecord?id=CVE-2026-6330, then? Offhand I'd think this one isn't exploitable, but we'll see more and more ML-KEM bugs, and some of them will be severe vulnerabilities.

    Post summary

    The post references CVE-2026-6330 but provides no technical details, exploits, or mitigation information, merely speculating about its severity.

    15045103.5K
    24.0K followersView on X
  • Daniel J. Bernstein@hashbreaker
    General

    24 June 2026: IETF TLS WG chairs call another vote on allowing ECC to be dropped from ECC+ML-KEM. https://www.cve.org/CVERecord?id=CVE-2026-6330 is dated 25 June 2026. Nothing to see here, that's the last ML-KEM bug ever, just bad timing, move along now.

    Post summary

    The post briefly notes a vote regarding the deletion of ECC from the ECC+ML-KEM suite and comments on the CVE, but does not provide detailed disclosure, PoC, exploitation evidence, or mitigation.

    1502442.9K
    24.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6330 The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 securit… https://www.cve.org/CVERecord?id=CVE-2026-6330 ----- Traducción: CVE-2026-6330 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑6330, explaining a cryptographic implementation flaw that weakens IND‑CCA2 security, but it provides no PoC, exploit code, or patch details.

    0000044
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6330 The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 securit… https://www.cve.org/CVERecord?id=CVE-2026-6330

    Post summary

    The text announces CVE‑2026‑6330, describing a technical flaw in the ML‑KEM ARM64 NEON ciphertext comparison that compromises IND‑CCA2 security, but it does not provide PoC, exploit code, or patch details.

    00000744
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more