wolfSSL 4.3.0 has mulmod code in wceccmulmod_ex in ecc.c that does not properly resist timing side-channel attacks.
{ "urgency": "not yet assigned" }