VYPR
High severity7.5NVD Advisory· Published Nov 21, 2025· Updated Jun 17, 2026

CVE-2025-12888

CVE-2025-12888

Description

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now turned on as the default for Xtensa.

Affected products

3
  • WolfSSL/Wolfssl3 versions
    cpe:2.3:a:wolfssl:wolfssl:5.8.2:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:wolfssl:wolfssl:5.8.2:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.