Nonce Management Vulnerability in wolfEngine TLS Implementation
CVE-2026-81341

6.5MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2026

What is CVE-2026-81341?

The wolfEngine product, prior to version 1.4.1, exhibits a vulnerability where the explicit nonce for AES-CCM cipher in TLS 1.2 and DTLS 1.2 is sourced erroneously from the record input buffer. This implementation flaw results in an identical key and nonce being used across multiple records within the same connection. Consequently, this can lead to weakened confidentiality, as the same keystream is used for multiple encrypted records, and may also allow for integrity issues, such as the potential for authentication tag forgery. It is important to note that AES-GCM and TLS 1.3 are not impacted by this vulnerability, and AES-CCM cipher suites are not enabled by default, thereby limiting the scope of exposure.

Affected Version(s)

wolfEngine 0 <= 1.4.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wolfSSL security team
.