<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[wolfSSL - Embedded SSL Library — wolfSSL 5.9.4 Release Blog]]></title>
	<link rel="self" href="https://www.wolfssl.com/forums/feed-atom-topic2579.xml" />
	<updated>2026-09-28T21:16:58Z</updated>
	<generator>PunBB</generator>
	<id>https://www.wolfssl.com/forums/topic2579-wolfssl-594-release-blog.html</id>
		<entry>
			<title type="html"><![CDATA[wolfSSL 5.9.4 Release Blog]]></title>
			<link rel="alternate" href="https://www.wolfssl.com/forums/post8941.html#p8941" />
			<content type="html"><![CDATA[<p><a href="https://www.wolfssl.com/products/wolfssl/">wolfSSL 5.9.4</a> is now available with new cryptographic algorithms, expanded post-quantum support, new hardware ports, significant assembly performance work, and a number of vulnerability fixes. Users are always recommended to stay up to date with wolfSSL releases. In this release the use cases affected by high severity reports are: trusted peer certificates (WOLFSSL_TRUST_PEER_CERT, including builds using OPENSSL_COMPATIBLE_DEFAULTS such as –enable-nginx, –enable-haproxy, –enable-all and –enable-distro), client-side multiple OCSP response stapling (HAVE_CERTIFICATE_STATUS_REQUEST_V2 with WOLFSSL_CSR2_OCSP_MULTI), and client-side Raw Public Keys (–enable-rpk, –enable-all, –enable-distro).</p><p><span class="bbu"><strong>Vulnerabilities</strong></span><br />This release addresses 11 CVEs (3 high, 4 medium, 4 low), down from 32 in 5.9.2. Most of them apply only to specific, non-default build configurations or API usage. Highlights include certificate validation fixes for name constraints, trusted peer matching and OCSP/CRL fallback, a (D)TLS 1.2 client ChangeCipherSpec ordering fix, and a session cache reference fix for TLS 1.2 resumption. Thanks to all the researchers who responsibly disclosed issues, including the Anthropic OSS program, Cantina Security, Jorge Milla (Pig-Tail), PathDiff, the Fuzz0x team, Jack Lloyd, Ben Smyth, and several independent contributors.</p><p>For the full list of vulnerabilities addressed, visit the <a href="https://www.wolfssl.com/docs/security-vulnerabilities/">wolfSSL Vulnerability Page</a>.</p><p><span class="bbu"><strong>Important Notes</strong></span><br /></p><ul><li><p><strong>liboqs is no longer used for any algorithm</strong>. Falcon now has a native wolfCrypt implementation, and the liboqs dependency and its configure and CMake options have been removed.</p></li></ul><ul><li><p>Certificates carrying trailing bytes after the DER structure are now rejected unless WOLFSSL_NO_ASN_STRICT is defined.</p></li></ul><ul><li><p>–disable-tlsv12 now truly compiles TLS 1.2 out, and WC_RNG gains a per-instance lock and fork handlers by default so one RNG can be shared between threads and across fork().</p></li></ul><ul><li><p>Under FIPS, HMAC-MD5 is rejected, short AES-GCM IVs return FIPS_BAD_VALUE_E, the CMAC minimum tag is 64 bits, and RSA-PSS salts longer than the hash are refused (FIPS 186-5).</p></li></ul><p><span class="bbu"><strong>New Features</strong></span><br /></p><ul><li><p><strong>New algorithms</strong>: Argon2 (RFC 9106) password hashing, AES-GCM-SIV (RFC 8452), KMAC and cSHAKE (SP 800-185), AES Key Wrap with Padding (RFC 5649), and a Time-Stamp Protocol (RFC 3161) implementation.</p></li></ul><ul><li><p>–enable-tinytls13 — a TLS 1.3-only footprint profile (PSK + ECDHE floor with optional minimal X.509).</p></li></ul><ul><li><p><strong>TLS receive read-ahead</strong> (–enable-readahead) to cut the number of recv() calls per record, plus zero-copy AEAD encryption on the send path.</p></li></ul><ul><li><p><strong>Runtime policy APIs</strong> to require an external PSK in (D)TLS 1.3 and to enforce Extended Master Secret.</p></li></ul><ul><li><p><strong>SBOM generation</strong> with make sbom (SPDX 2.3 + CycloneDX 1.6) and make bomsh (OmniBOR build provenance) to support EU Cyber Resilience Act compliance.</p></li></ul><ul><li><p>WOLFSSL_X509_TINY and WOLFSSL_X509_VERIFY_ONLY certificate parser profiles, and true zero-allocation X.509 verification for WOLFSSL_NO_MALLOC builds.</p></li></ul><p><span class="bbu"><strong>Post-Quantum Cryptography Updates</strong></span><br /></p><ul><li><p><strong>Native Falcon</strong> (levels 1 and 5) with crypto callbacks and ARM DSP / AArch64 NEON acceleration, replacing the liboqs wrapper</p></li></ul><ul><li><p><strong>FrodoKEM</strong> added with C and assembly for x86_64, AArch64, AArch32 and Thumb2, plus ASN.1 keys and X.509 certificates.</p></li></ul><ul><li><p><strong>SLH-DSA (FIPS 205) authentication</strong> in the TLS 1.3 and DTLS 1.3 handshake for all twelve parameter sets.</p></li></ul><ul><li><p><strong>Post-quantum-only TLS 1.3 builds</strong> — ML-KEM key exchange with ML-DSA or SLH-DSA authentication and no RSA/ECC/DH.</p></li></ul><ul><li><p>ML-DSA for PKCS#7/CMS SignedData (RFC 9882) and in the OpenSSL compatibility layer.</p></li></ul><ul><li><p>AVX512 assembly for ML-KEM and ML-DSA, a constant-time ML-DSA low-bits check, and a new –enable-all-quantum-crypto bundle.</p></li></ul><p><span class="bbu"><strong>TLS and DTLS Improvements</strong></span><br /></p><ul><li><p>RFC 9846 (TLS 1.3 update) conformance work, including the general_error alert, key update limits, and NewSessionTicket hardening.</p></li></ul><ul><li><p>Extended Key Usage is now enforced on chain-supplied intermediate CAs.</p></li></ul><ul><li><p>RFC 5746 renegotiation_info is checked by default on TLS 1.2 clients, and SHA-1 signature schemes are no longer offered by default for TLS 1.2.</p></li></ul><ul><li><p>DTLS: rotatable cookie secrets, DTLS 1.2 Connection ID support, stricter peer address handling, and many DTLS 1.3 correctness fixes.</p></li></ul><ul><li><p>New dtls_bench DTLS throughput benchmark with an optimized DTLS send path.</p></li></ul><p><span class="bbu"><strong>Hardware and Embedded Ports</strong></span><br /></p><ul><li><p><strong>STM32 bare-metal crypto port</strong> (no HAL required) with DHUK (Device Hardware Unique Key) hardware-protected keys, validated on a 27-board reference matrix spanning about 20 STM32 families, plus STM32V8 (Cortex-M85) and STM32CubeMX2 support.</p></li></ul><ul><li><p>New ports for the RealTek AmebaPro2, WISeKey/SealSQ VaultIC, Vorago VA416x0 TRNG, and the TI C2000 C28x DSP family.</p></li></ul><ul><li><p>SE050/SE05x enhancements including on-chip key generation, SCP03 key rotation and attestation, plus Zephyr, NetX, Renesas, NXP and other port fixes.</p></li></ul><p><span class="bbu"><strong>Assembly and Performance</strong></span><br /></p><ul><li><p>New Intel x64 AES assembly using AVX512/VAES, AVX512 ChaCha20-Poly1305, and AVX512 IFMA X25519/Ed25519.</p></li></ul><ul><li><p>AArch64 and ARM32 runtime CPU feature dispatch, new PPC64/PPC32 AES and SHA assembly, and a full RISC-V 64-bit SP implementation.</p></li></ul><p><span class="bbu"><strong>Build System</strong></span><br /></p><ul><li><p>CMake gains ~100 options and 37 application bundles to match autotools.</p></li></ul><ul><li><p>Linux and FreeBSD kernel module improvements, and FIPS v7 readiness work.</p></li></ul><p><span class="bbu"><strong>Rust Wrapper</strong></span><br /></p><ul><li><p>Released versions 2.1.0 and 2.2.0 of the wolfssl-wolfcrypt Rust crate, with the dilithium module renamed to mldsa and numerous build-option gating fixes.</p></li></ul><p><span class="bbu"><strong>Get the Update</strong></span><br />Dive into the full <a href="https://github.com/wolfSSL/wolfssl/blob/master/ChangeLog.md">ChangeLog</a> for a complete list of changes.</p><p>If you have any questions about any of the above, please contact us at <a href="mailto:facts@wolfssl.com">facts@wolfssl.com</a> or call us at +1 425 245 8247.</p><p><strong><a href="https://www.wolfssl.com/download/">Download</a> wolfSSL Now</strong></p>]]></content>
			<author>
				<name><![CDATA[shizuka]]></name>
				<uri>https://www.wolfssl.com/forums/user5631.html</uri>
			</author>
			<updated>2026-09-28T21:16:58Z</updated>
			<id>https://www.wolfssl.com/forums/post8941.html#p8941</id>
		</entry>
</feed>
