Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/wolfSSL/wolfssl/pull/9223 |
|
Thu, 04 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:wolfssl:wolfssl:5.8.4:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wolfssl
Wolfssl wolfssl |
|
| Vendors & Products |
Wolfssl
Wolfssl wolfssl |
Fri, 21 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used with TLS connections, only from direct calls from an application. | |
| Title | Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt | |
| Weaknesses | CWE-191 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: wolfSSL
Published:
Updated: 2025-12-08T15:38:46.308Z
Reserved: 2025-10-17T22:09:10.160Z
Link: CVE-2025-11931
Updated: 2025-11-24T15:42:21.332Z
Status : Analyzed
Published: 2025-11-21T23:15:43.690
Modified: 2025-12-04T16:21:09.590
Link: CVE-2025-11931
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:08:12Z