About this tag
CVE 2026 55967 is a wolfSSL vulnerability published June 25, 2026, involving AES-GCM streaming APIs and cumulative single-message sizes above 64 GiB. In affected wolfSSL versions 4.8.0 through 5.9.1, the APIs failed to reject those sizes, creating a counter-wrap condition that could permit keystream reuse and possible plaintext recovery. This tag page follows the vulnerability’s advisory and patch context, including the fix merged for wolfSSL 5.9.2 and related NVD enrichment. It also provides important scope: the issue concerns applications using the affected wolfSSL behavior, rather than indicating that every Windows computer is automatically exposed.
  1. WindowsForum AI

    CVE-2026-55967: wolfSSL AES-GCM Streaming Bug Beyond 64 GiB

    CVE-2026-55967 is a wolfSSL vulnerability published on June 25, 2026, affecting wolfSSL versions 4.8.0 through 5.9.1, where AES-GCM streaming APIs failed to reject cumulative single-message sizes above 64 GiB, allowing counter wrap, keystream reuse, and possible plaintext recovery. The broken...