CVE-2026-55967
EUVD-2026-3949325.06.2026, 18:16
AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent plaintext recovery.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| wolfssl | wolfssl | 4.8.0 ≤ 𝑥 ≤ 5.9.1 | CNA |
Debian Releases
Common Weakness Enumeration