Weak Digest Algorithm Vulnerability in wolfSSL TLS 1.2
CVE-2025-12889

2.3LOW

Key Information:

Vendor

Wolfssl

Status
Vendor
CVE Published:
21 November 2025

What is CVE-2025-12889?

In TLS 1.2 connections, the wolfSSL implementation allows clients to select weaker digest algorithms when forming connections. This results in potential security risks, as these weaker digests can compromise the authentication and integrity of the secure communication, enabling attackers to exploit the protocol and potentially intercept sensitive data. Users are advised to ensure stronger algorithms are enforced in their configurations to mitigate this risk.

Affected Version(s)

wolfSSL 0 < 5.8.4

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jaehun Lee from Pohang University of Science and Technology (POSTECH)
.