PT-2026-52561 · Wolfssl+4 · Wolfssl+1

·

CVE-2026-10512

·

Published

2026-06-25

·

Updated

2026-07-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The X25519 x86 64 assembly implementation fails to clear the most significant bit during the final modular reduction. This occurs because the final carry-propagation chains in the x64 and AVX2 reduction routines could overflow into the top bit, and the high limb was not masked afterward. Consequently, the computed result may not be fully reduced modulo the field prime 2^255 - 19, leaving the field element in a non-canonical form. This can lead to incorrect results from scalar multiplication and potentially the generation of an incorrect shared secret.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10512
JLSEC-2026-695

Affected Products

Wolfssl
Wolfssl Jll