CVE-2026-2645
In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could incorrectly accept the CertificateVerify message before the ClientKeyExchange message had been received. This issue affects wolfSSL before 5.8.4 (wolfSSL 5.8.2 and earlier is vulnerable, 5.8.4 is not vulnerable). In 5.8.4 wolfSSL would detect the issue later in the handshake. 5.9.0 was further hardened to catch the issue earlier in the handshake.
- Affected products
- Wolfssl
- Wolfssl
- < 5.8.4
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.1% (3th percentile)
- Weakness
- CWE-358
- NVD status
- Analyzed
- Published
- 2026-03-19
- Attack patterns
- CAPEC-218
CVE-2026-2645 at NVD
No indexed exploits for CVE-2026-2645 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-2645 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.