PT-2026-31861 · Wolfssl · Wolfssl

Muhammad Arya

·

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-5188

CVSS v4.0

2.3

Low

AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions wolfSSL (affected versions not specified)
Description An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certificate can specify an entry length larger than the enclosing sequence, causing the internal length counter to wrap during parsing. This results in incorrect handling of certificate data. The issue is limited to configurations using the original ASN.1 parsing implementation which is off by default.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Underflow

Weakness Enumeration

Related Identifiers

CVE-2026-5188

Affected Products

Wolfssl