HMAC-BLAKE2 APIs Vulnerability in wolfSSL Software
CVE-2026-8720

5.9MEDIUM

Key Information:

Vendor

Wolfssl

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-8720?

The HMAC-BLAKE2 APIs in wolfSSL have a flaw that occurs when the key length exceeds the BLAKE2 block size. In this case, the MAC (Message Authentication Code) generated is vulnerable as it fails to account for the input message. Instead of producing a MAC dependent on both the key and the input message, the running hash state is reinitialized, leading to a scenario where the MAC only reflects the key. This flaw, introduced in wolfSSL version 5.9.0, raises significant security concerns regarding the integrity of authenticated messages.

Affected Version(s)

wolfSSL 5.9.0 <= 5.9.1

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.