CVE-2026-93304 Overview
CVE-2026-93304 is a protocol state machine flaw in wolfSSL's (D)TLS 1.2 client implementation. A client accepts a ChangeCipherSpec message before transmitting its own ClientKeyExchange. No master secret exists at that point, so the client installs read keys derived from a deterministic known value and validates the server's Finished message against that same key. An attacker can complete the handshake in place of the legitimate server and deliver data the client treats as authentic. The issue is categorized under [CWE-696] (Incorrect Behavior Order).
Critical Impact
An attacker can inject authenticated application data into a wolfSSL client session. Pre-Shared Key (PSK) connections are exploitable by any rogue server without knowledge of the PSK.
Affected Products
- wolfSSL (D)TLS 1.2 client implementations
- DTLS 1.2 clients receiving out-of-order datagrams
- TLS 1.2 clients using wolfSSL_inject() or read-ahead mode
Discovery Timeline
- 2026-09-27 - CVE-2026-93304 published to NVD
- 2026-09-29 - Last updated in NVD database
Technical Details for CVE-2026-93304
Vulnerability Analysis
The flaw resides in how wolfSSL's (D)TLS 1.2 client orders handshake state transitions. Under correct protocol behavior, a client must send ClientKeyExchange and derive a master secret before processing any ChangeCipherSpec message. The affected client accepts an out-of-order ChangeCipherSpec before performing key exchange. At that moment, no master secret is available, so the client falls back to deriving read keys from a deterministic, known value.
Because both parties can compute this deterministic value, an attacker can construct a valid Finished message that passes the client's verification. The handshake appears to complete successfully. The attacker then sends application-layer data that the client decrypts and accepts as authentic server traffic.
The client's write keys are still derived from legitimate randomness, so outbound traffic remains confidential to the attacker. The genuine server never completes its side of the handshake. The impact is a one-directional injection channel, which maps to the Vulnerability Integrity Low (VI:L) rating.
Root Cause
The root cause is improper enforcement of handshake message ordering ([CWE-696]). The state machine permits key installation based on uninitialized secret material instead of rejecting the premature ChangeCipherSpec record.
Attack Vector
DTLS 1.2 clients are directly exposed because a single UDP datagram can carry the out-of-order records to the client's socket. TLS 1.2 clients are exposed when the application feeds received bytes via wolfSSL_inject() or enables read-ahead buffering, allowing multiple records to be processed together.
For certificate-based cipher suites, the attacker must occupy a man-in-the-middle position between client and server. For PSK suites, any attacker that can reach the client as a fake server succeeds without possessing the PSK. Detailed remediation is documented in the wolfSSL GitHub Pull Request #11458.
Detection Methods for CVE-2026-93304
Indicators of Compromise
- Unexpected ChangeCipherSpec records appearing before ClientKeyExchange in captured handshake traces.
- DTLS sessions where the client reports a completed handshake but the server logs no corresponding session establishment.
- Application-layer anomalies in PSK-based wolfSSL clients receiving data from unverified endpoints.
Detection Strategies
- Inspect TLS and DTLS handshake message ordering at network sensors and flag out-of-sequence ChangeCipherSpec records.
- Correlate client-side successful handshake events with server-side handshake completion logs to surface mismatches.
- Audit applications linking wolfSSL for use of wolfSSL_inject() or read-ahead configuration, which expand the TLS attack surface.
Monitoring Recommendations
- Enable verbose wolfSSL logging on client deployments to capture handshake state transitions.
- Monitor DTLS endpoints exposed to untrusted networks for repeated handshake retries from spoofed source addresses.
- Track outbound connections from embedded and IoT devices using wolfSSL for anomalous session durations or payloads.
How to Mitigate CVE-2026-93304
Immediate Actions Required
- Inventory all applications, firmware, and embedded devices that link against wolfSSL for (D)TLS 1.2 client functionality.
- Apply the upstream fix from wolfSSL Pull Request #11458 and rebuild affected binaries.
- Prioritize remediation for deployments using PSK cipher suites, which do not require man-in-the-middle positioning to exploit.
Patch Information
The fix is delivered via wolfSSL Pull Request #11458, which corrects the client state machine to reject ChangeCipherSpec records received before the client transmits ClientKeyExchange. Consumers should upgrade to the first stable wolfSSL release that incorporates this merge commit.
Workarounds
- Disable PSK cipher suites in wolfSSL client configurations where feasible, since PSK deployments are exploitable without MITM access.
- Avoid using wolfSSL_inject() and disable read-ahead mode on TLS 1.2 clients until the patch is applied.
- Prefer TLS 1.3, which uses a different handshake and key schedule not affected by this ordering flaw.
- Restrict DTLS 1.2 client exposure to trusted network segments and authenticated peers only.
# Configuration example: build wolfSSL without PSK and without read-ahead support
./configure --disable-psk --disable-readahead
make && sudo make install
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.