CVE-2026-81019 HIGH

CVE-2026-81019: wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record

Vendor Wolfssl Inc.
Product wolfProvider
Weakness CWE-323
Published August 28, 2026
Last update August 28, 2026

CVSS base score

7.4/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known record recovers the others) and leaks the GHASH authentication key, enabling authentication tag forgery. AES-CCM, TLS 1.3, and non-TLS use of the cipher are not affected.

Key dates

02Disclosure timeline

August 28, 2026 CVE published
August 28, 2026 Record updated