PT-2026-26365 · Wolfssl · Wolfssl

Kunyuk

+1

·

Published

2026-03-19

·

Updated

2026-04-30

·

CVE-2026-3229

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions wolfssl (affected versions not specified)
Description An integer overflow issue was identified in the wolfssl add to chain function, leading to heap corruption when certificate data exceeded the bounds of the certificate buffer. The function is utilized by the following API endpoints: wolfSSL CTX add extra chain cert, wolfSSL CTX add1 chain cert, and wolfSSL add0 chain cert. This issue is not remotely exploitable and requires a compromise of the application context loading certificates. The issue is triggered when using 3rd party compatibility features: enable-opensslall, enable-opensslextra, enable-lighty, enable-stunnel, enable-nginx, and enable-haproxy.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3229

Affected Products

Wolfssl