wolfSSL 5.9.4 is now available with new cryptographic algorithms, expanded post-quantum support, new hardware ports, significant assembly performance work, and a number of vulnerability fixes. Users are always recommended to stay up to date with wolfSSL releases. In this release the use cases affected by high severity reports are: trusted peer certificates (WOLFSSL_TRUST_PEER_CERT, including builds using OPENSSL_COMPATIBLE_DEFAULTS such as –enable-nginx, –enable-haproxy, –enable-all and –enable-distro), client-side multiple OCSP response stapling (HAVE_CERTIFICATE_STATUS_REQUEST_V2 with WOLFSSL_CSR2_OCSP_MULTI), and client-side Raw Public Keys (–enable-rpk, –enable-all, –enable-distro).
Vulnerabilities
This release addresses 11 CVEs (3 high, 4 medium, 4 low), down from 32 in 5.9.2. Most of them apply only to specific, non-default build configurations or API usage. Highlights include certificate validation fixes for name constraints, trusted peer matching and OCSP/CRL fallback, a (D)TLS 1.2 client ChangeCipherSpec ordering fix, and a session cache reference fix for TLS 1.2 resumption. Thanks to all the researchers who responsibly disclosed issues, including the Anthropic OSS program, Cantina Security, Jorge Milla (Pig-Tail), PathDiff, the Fuzz0x team, Jack Lloyd, Ben Smyth, and several independent contributors.
For the full list of vulnerabilities addressed, visit the wolfSSL Vulnerability Page.
Important Notes
- liboqs is no longer used for any algorithm. Falcon now has a native wolfCrypt implementation, and the liboqs dependency and its configure and CMake options have been removed.
- Certificates carrying trailing bytes after the DER structure are now rejected unless WOLFSSL_NO_ASN_STRICT is defined.
- –disable-tlsv12 now truly compiles TLS 1.2 out, and WC_RNG gains a per-instance lock and fork handlers by default so one RNG can be shared between threads and across fork().
- Under FIPS, HMAC-MD5 is rejected, short AES-GCM IVs return FIPS_BAD_VALUE_E, the CMAC minimum tag is 64 bits, and RSA-PSS salts longer than the hash are refused (FIPS 186-5).
New Features
- New algorithms: Argon2 (RFC 9106) password hashing, AES-GCM-SIV (RFC 8452), KMAC and cSHAKE (SP 800-185), AES Key Wrap with Padding (RFC 5649), and a Time-Stamp Protocol (RFC 3161) implementation.
- –enable-tinytls13 — a TLS 1.3-only footprint profile (PSK + ECDHE floor with optional minimal X.509).
- TLS receive read-ahead (–enable-readahead) to cut the number of recv() calls per record, plus zero-copy AEAD encryption on the send path.
- Runtime policy APIs to require an external PSK in (D)TLS 1.3 and to enforce Extended Master Secret.
- SBOM generation with make sbom (SPDX 2.3 + CycloneDX 1.6) and make bomsh (OmniBOR build provenance) to support EU Cyber Resilience Act compliance.
- WOLFSSL_X509_TINY and WOLFSSL_X509_VERIFY_ONLY certificate parser profiles, and true zero-allocation X.509 verification for WOLFSSL_NO_MALLOC builds.
Post-Quantum Cryptography Updates
- Native Falcon (levels 1 and 5) with crypto callbacks and ARM DSP / AArch64 NEON acceleration, replacing the liboqs wrapper.
- FrodoKEM added with C and assembly for x86_64, AArch64, AArch32 and Thumb2, plus ASN.1 keys and X.509 certificates.
- SLH-DSA (FIPS 205) authentication in the TLS 1.3 and DTLS 1.3 handshake for all twelve parameter sets.
- Post-quantum-only TLS 1.3 builds — ML-KEM key exchange with ML-DSA or SLH-DSA authentication and no RSA/ECC/DH.
- ML-DSA for PKCS#7/CMS SignedData (RFC 9882) and in the OpenSSL compatibility layer.
- AVX512 assembly for ML-KEM and ML-DSA, a constant-time ML-DSA low-bits check, and a new –enable-all-quantum-crypto bundle.
TLS and DTLS Improvements
- RFC 9846 (TLS 1.3 update) conformance work, including the general_error alert, key update limits, and NewSessionTicket hardening.
- Extended Key Usage is now enforced on chain-supplied intermediate CAs.
- RFC 5746 renegotiation_info is checked by default on TLS 1.2 clients, and SHA-1 signature schemes are no longer offered by default for TLS 1.2.
- DTLS: rotatable cookie secrets, DTLS 1.2 Connection ID support, stricter peer address handling, and many DTLS 1.3 correctness fixes.
- New dtls_bench DTLS throughput benchmark with an optimized DTLS send path.
Hardware and Embedded Ports
- STM32 bare-metal crypto port (no HAL required) with DHUK (Device Hardware Unique Key) hardware-protected keys, validated on a 27-board reference matrix spanning about 20 STM32 families, plus STM32V8 (Cortex-M85) and STM32CubeMX2 support.
- New ports for the RealTek AmebaPro2, WISeKey/SealSQ VaultIC, Vorago VA416x0 TRNG, and the TI C2000 C28x DSP family.
- SE050/SE05x enhancements including on-chip key generation, SCP03 key rotation and attestation, plus Zephyr, NetX, Renesas, NXP and other port fixes.
Assembly and Performance
- New Intel x64 AES assembly using AVX512/VAES, AVX512 ChaCha20-Poly1305, and AVX512 IFMA X25519/Ed25519.
- AArch64 and ARM32 runtime CPU feature dispatch, new PPC64/PPC32 AES and SHA assembly, and a full RISC-V 64-bit SP implementation.
Build System
- CMake gains ~100 options and 37 application bundles to match autotools.
- Linux and FreeBSD kernel module improvements, and FIPS v7 readiness work.
Rust Wrapper
- Released versions 2.1.0 and 2.2.0 of the wolfssl-wolfcrypt Rust crate, with the dilithium module renamed to mldsa and numerous build-option gating fixes.
Get the Update
Dive into the full ChangeLog for a complete list of changes.
If you have any questions about any of the above, please contact us at facts@wolfssl.com or call us at +1 425 245 8247.
Download wolfSSL Now

