HMAC-BLAKE2 APIs Vulnerability in wolfSSL Software
CVE-2026-8720
5.9MEDIUM
What is CVE-2026-8720?
The HMAC-BLAKE2 APIs in wolfSSL have a flaw that occurs when the key length exceeds the BLAKE2 block size. In this case, the MAC (Message Authentication Code) generated is vulnerable as it fails to account for the input message. Instead of producing a MAC dependent on both the key and the input message, the running hash state is reinitialized, leading to a scenario where the MAC only reflects the key. This flaw, introduced in wolfSSL version 5.9.0, raises significant security concerns regarding the integrity of authenticated messages.
Affected Version(s)
wolfSSL 5.9.0 <= 5.9.1
