Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-3230

Опубликовано: 31 мар. 2026
Источник: msrc
EPSS Низкий

Описание

Improper key_share validation in TLS 1.3 HelloRetryRequest

EPSS

Процентиль: 11%
0.00209
Низкий

Связанные уязвимости

CVSS3: 2.7
ubuntu
5 месяцев назад

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

CVSS3: 2.7
nvd
5 месяцев назад

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

CVSS3: 2.7
debian
5 месяцев назад

Missing required cryptographic step in the TLS 1.3 client HelloRetryRe ...

CVSS3: 2.7
github
5 месяцев назад

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.

EPSS

Процентиль: 11%
0.00209
Низкий