Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mmq-prpj-ww9q

Опубликовано: 22 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 5.3

Описание

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.

EPSS

Процентиль: 25%
0.00085
Низкий

6.3 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
21 день назад

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.

CVSS3: 5.3
nvd
21 день назад

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.

msrc
17 дней назад

Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello

CVSS3: 5.3
debian
21 день назад

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolf ...

EPSS

Процентиль: 25%
0.00085
Низкий

6.3 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-20