#VU125934 Reusing a Nonce, Key Pair in Encryption in wolfSSL - CVE-2026-5446
Published: April 14, 2026
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to compromise message confidentiality and integrity.
The vulnerability exists due to nonce reuse in TLS 1.2 record encryption when using ARIA-GCM. A remote attacker can exploit repeated nonces to compromise message confidentiality and integrity.
ARIA cipher support requires the proprietary MagicCrypto library and the --enable-aria build option.