CVE-2026-81020(wolfssl / wolfengine)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known record recovers the others) and leaks the GHASH authentication key, enabling authentication tag forgery. AES-CCM, TLS 1.3, and non-TLS use of the cipher are not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-323

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfengine

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
wolfengine

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-30: 109-30
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    🚨 HIGH SEVERITY: CVE-2026-81020 (CVSS 7.4) wolfEngine <1[.]4[.]1 reuses AES-GCM nonces in TLS 1.2/DTLS 1.2, exposing keystreams & enabling auth tag forgery. Affected: TLS 1.2 & DTLS 1.2 connections Action: Update to wolfEngine 1.4.1+ #CVE #Vulnerability #PatchNow https://t.co/A5Cz6PMzep

    0000030
    141 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfengine---

Explore more