CVE-2026-81020CWE-323

CVE-2026-81020

High · published August 28, 2026

CVSS v3.1
7.4
EPSS
0%
Percentile
14.6
In the wild
Unconfirmed
What it is

wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known record recovers the others) and leaks the GHASH authentication key, enabling authentication tag forgery. AES-CCM, TLS 1.3, and non-TLS use of the cipher are not affected.

The record
Technical detail
CVSS v3.1
7.4 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00237 · 14.6th percentile
Weakness
CWE-323 · Reusing a Nonce, Key Pair in Encryption
Published
2026-08-28T20:18Z
References (1)
EPSS history
Timeline
  • 30 AUG 16:19Z
    EPSS moved — → 0%
    epss
  • 28 AUG 14:42Z
    wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
    cvelistv5