Topic: wolfSSL 5.9.4 Release Blog
wolfSSL 5.9.4 is now available with new cryptographic algorithms, expanded post-quantum support, new hardware ports, significant assembly performance work, and a number of vulnerability fixes. Users are always recommended to stay up to date with wolfSSL releases. In this release the use cases affected by high severity reports are: trusted peer certificates (WOLFSSL_TRUST_PEER_CERT, including builds using OPENSSL_COMPATIBLE_DEFAULTS such as –enable-nginx, –enable-haproxy, –enable-all and –enable-distro), client-side multiple OCSP response stapling (HAVE_CERTIFICATE_STATUS_REQUEST_V2 with WOLFSSL_CSR2_OCSP_MULTI), and client-side Raw Public Keys (–enable-rpk, –enable-all, –enable-distro).
Vulnerabilities
This release addresses 11 CVEs (3 high, 4 medium, 4 low), down from 32 in 5.9.2. Most of them apply only to specific, non-default build configurations or API usage. Highlights include certificate validation fixes for name constraints, trusted peer matching and OCSP/CRL fallback, a (D)TLS 1.2 client ChangeCipherSpec ordering fix, and a session cache reference fix for TLS 1.2 resumption. Thanks to all the researchers who responsibly disclosed issues, including the Anthropic OSS program, Cantina Security, Jorge Milla (Pig-Tail), PathDiff, the Fuzz0x team, Jack Lloyd, Ben Smyth, and several independent contributors.
For the full list of vulnerabilities addressed, visit the wolfSSL Vulnerability Page.
Important Notes
liboqs is no longer used for any algorithm. Falcon now has a native wolfCrypt implementation, and the liboqs dependency and its configure and CMake options have been removed.
Certificates carrying trailing bytes after the DER structure are now rejected unless WOLFSSL_NO_ASN_STRICT is defined.
–disable-tlsv12 now truly compiles TLS 1.2 out, and WC_RNG gains a per-instance lock and fork handlers by default so one RNG can be shared between threads and across fork().
Under FIPS, HMAC-MD5 is rejected, short AES-GCM IVs return FIPS_BAD_VALUE_E, the CMAC minimum tag is 64 bits, and RSA-PSS salts longer than the hash are refused (FIPS 186-5).
New Features
New algorithms: Argon2 (RFC 9106) password hashing, AES-GCM-SIV (RFC 8452), KMAC and cSHAKE (SP 800-185), AES Key Wrap with Padding (RFC 5649), and a Time-Stamp Protocol (RFC 3161) implementation.
–enable-tinytls13 — a TLS 1.3-only footprint profile (PSK + ECDHE floor with optional minimal X.509).
TLS receive read-ahead (–enable-readahead) to cut the number of recv() calls per record, plus zero-copy AEAD encryption on the send path.
Runtime policy APIs to require an external PSK in (D)TLS 1.3 and to enforce Extended Master Secret.
SBOM generation with make sbom (SPDX 2.3 + CycloneDX 1.6) and make bomsh (OmniBOR build provenance) to support EU Cyber Resilience Act compliance.
WOLFSSL_X509_TINY and WOLFSSL_X509_VERIFY_ONLY certificate parser profiles, and true zero-allocation X.509 verification for WOLFSSL_NO_MALLOC builds.
Post-Quantum Cryptography Updates
Native Falcon (levels 1 and 5) with crypto callbacks and ARM DSP / AArch64 NEON acceleration, replacing the liboqs wrapper
FrodoKEM added with C and assembly for x86_64, AArch64, AArch32 and Thumb2, plus ASN.1 keys and X.509 certificates.
SLH-DSA (FIPS 205) authentication in the TLS 1.3 and DTLS 1.3 handshake for all twelve parameter sets.
Post-quantum-only TLS 1.3 builds — ML-KEM key exchange with ML-DSA or SLH-DSA authentication and no RSA/ECC/DH.
ML-DSA for PKCS#7/CMS SignedData (RFC 9882) and in the OpenSSL compatibility layer.
AVX512 assembly for ML-KEM and ML-DSA, a constant-time ML-DSA low-bits check, and a new –enable-all-quantum-crypto bundle.
TLS and DTLS Improvements
RFC 9846 (TLS 1.3 update) conformance work, including the general_error alert, key update limits, and NewSessionTicket hardening.
Extended Key Usage is now enforced on chain-supplied intermediate CAs.
RFC 5746 renegotiation_info is checked by default on TLS 1.2 clients, and SHA-1 signature schemes are no longer offered by default for TLS 1.2.
DTLS: rotatable cookie secrets, DTLS 1.2 Connection ID support, stricter peer address handling, and many DTLS 1.3 correctness fixes.
New dtls_bench DTLS throughput benchmark with an optimized DTLS send path.
Hardware and Embedded Ports
STM32 bare-metal crypto port (no HAL required) with DHUK (Device Hardware Unique Key) hardware-protected keys, validated on a 27-board reference matrix spanning about 20 STM32 families, plus STM32V8 (Cortex-M85) and STM32CubeMX2 support.
New ports for the RealTek AmebaPro2, WISeKey/SealSQ VaultIC, Vorago VA416x0 TRNG, and the TI C2000 C28x DSP family.
SE050/SE05x enhancements including on-chip key generation, SCP03 key rotation and attestation, plus Zephyr, NetX, Renesas, NXP and other port fixes.
Assembly and Performance
New Intel x64 AES assembly using AVX512/VAES, AVX512 ChaCha20-Poly1305, and AVX512 IFMA X25519/Ed25519.
AArch64 and ARM32 runtime CPU feature dispatch, new PPC64/PPC32 AES and SHA assembly, and a full RISC-V 64-bit SP implementation.
Build System
CMake gains ~100 options and 37 application bundles to match autotools.
Linux and FreeBSD kernel module improvements, and FIPS v7 readiness work.
Rust Wrapper
Released versions 2.1.0 and 2.2.0 of the wolfssl-wolfcrypt Rust crate, with the dilithium module renamed to mldsa and numerous build-option gating fixes.
Get the Update
Dive into the full ChangeLog for a complete list of changes.
If you have any questions about any of the above, please contact us at facts@wolfssl.com or call us at +1 425 245 8247.
Download wolfSSL Now