CVE-2026-93304
CVE-2026-93304 is a low-severity vulnerability in Wolfssl with a CVSS 3.x base score of 3.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-696.
Key facts
- Severity: Low (CVSS 3.x base score 3.7)
- CVSS v4: 6.3
- EPSS exploit prediction: 0% (4th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-696
- Affected product: Wolfssl
- Published:
- Last modified:
Description
A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server's Finished against that same key. An out-of-order ChangeCipherSpec can therefore be used by an attacker to complete the handshake in place of the server and send data the client accepts as authentic. The client's own traffic still uses correctly derived keys, so the attacker cannot read it, and the genuine server never completes the handshake. DTLS 1.2 clients are exposed because a datagram read can deliver the out-of-order records on its own. TLS 1.2 clients are exposed when the application supplies received bytes with wolfSSL_inject() or enables read ahead. For certificate suites, the attacker must be in a man-in-the-middle position. For PSK (Pre Shared Key) connections, any fake server can succeed without knowing the PSK.
Frequently asked questions
- What is CVE-2026-93304?
- A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server's Finished against that same key. An out-of-order ChangeCipherSpec can therefore be used by an attacker to complete the handshake in place of the server and send data the client accepts as authentic. The client's own traffic still uses correctly derived keys, so the attacker cannot read it, and the genuine server never completes the handshake. DTLS 1.2 clients are exposed because a datagram read can deliver the out-of-order records on its own. TLS 1.2 clients are exposed when the application supplies received bytes with wolfSSL_inject() or enables read ahead. For certificate suites, the attacker must be in a man-in-the-middle position. For PSK (Pre Shared Key) connections, any fake server can succeed without knowing the PSK.
- How severe is CVE-2026-93304?
- CVE-2026-93304 has a CVSS 3.x base score of 3.7, rated low severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-93304 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (4th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-93304?
- CVE-2026-93304 affects Wolfssl. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-93304?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-93304 published?
- CVE-2026-93304 was published on 2026-09-27 and last updated on 2026-10-02.
References
Affected products (1)
- cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*
More vulnerabilities in Wolfssl
- CVE-2026-7531 — Critical (CVSS 9.8): Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in…
- CVE-2026-5264 — Critical (CVSS 9.8): Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that…
- CVE-2026-5187 — Critical (CVSS 9.8): Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds…
- CVE-2026-4395 — Critical (CVSS 9.8): Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote…
- CVE-2026-3849 — Critical (CVSS 9.8): Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH…
- CVE-2026-3549 — Critical (CVSS 9.8): Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a…
Other CWE-696 vulnerabilities
- CVE-2026-44108 — Critical (CVSS 9.8): Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system…
- CVE-2026-14169 — High (CVSS 8.1): Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted…
- CVE-2026-45033 — High (CVSS 7.8): GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security…
- CVE-2025-31485 — High (CVSS 7.5): API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL…
- CVE-2021-22569 — High (CVSS 7.5): An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that…
- CVE-2021-31379 — High (CVSS 7.5): An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS…