CVE-2026-3230 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-…
Low CVSS: 1.2

CVE-2026-3230

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.
Vendor
Wolfssl
Product
Wolfssl
CWE
CWE-20
Yayın Tarihi
2026-03-19 21:17:12
Güncelleme
2026-03-26 18:33:37
Source Identifier
facts@wolfssl.com
KEV Date Added
-

Kategoriler

Referanslar