CVE-2026-3547
published 2026-03-19CVE-2026-3547: Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.26%
17.2th percentile
Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is enabled for these 3rd party compatibility features: enable-apachehttpd, enable-bind, enable-curl, enable-haproxy, enable-hitch, enable-lighty, enable-jni, enable-nginx, enable-quic.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 5.9.0-0.1 (forky) | wolfssl 5.9.0-0.1 (forky) |
| msrc | azl3_mariadb_10.11.16-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_mariadb_10.6.24-1_on_cbl_mariner_2.0 | — | — |
| wolfssl | wolfssl | < 5.9.0 | 5.9.0 |
| wolfssl | wolfssl | >= 0 < 5.9.0-0.1 | 5.9.0-0.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slash
ghsa·2026-05-26
CVE-2026-23734 [CRITICAL] CWE-23 XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slash
XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slash
### Impact
It's possible to get access and read configuration files by using URLs such as `http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false`.
This can apparently be reproduced on Tomcat instances.
### Patches
This has been patched in 18.0.0-rc-1, 17.10.3, 17.4.9, 16.10.17.
### Workarounds
There is no known workaround, other than upgrading XWiki.
### References
* https://jira.xwiki.org/browse/XCOMMONS-3547
* https://github.com/xwiki/xwiki-commons/commit/a979cafd89f6a9c9c0b9ab19744d672df64429bf
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org
GHSA
GHSA-f377-557w-vjgv: Out-of-bounds read in ALPN parsing due to incomplete validation
ghsa_unreviewed·2026-03-19
CVE-2026-3547 [HIGH] CWE-125 GHSA-f377-557w-vjgv: Out-of-bounds read in ALPN parsing due to incomplete validation
Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is enabled for these 3rd party compatibility features: enable-apachehttpd, enable-bind, enable-curl, enable-haproxy, enable-hitch, enable-lighty, enable-jni, enable-nginx, enable-quic.
OSV
CVE-2026-3547: Out-of-bounds read in ALPN parsing due to incomplete validation
osv·2026-03-19·CVSS 7.5
CVE-2026-3547 [HIGH] CVE-2026-3547: Out-of-bounds read in ALPN parsing due to incomplete validation
Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is enabled for these 3rd party compatibility features: enable-apachehttpd, enable-bind, enable-curl, enable-haproxy, enable-hitch, enable-lighty, enable-jni, enable-nginx, enable-quic.
Microsoft
wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation
vendor_msrc·2026-03-10·CVSS 7.5
CVE-2026-3547 [HIGH] CWE-125 wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation
wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation
Mariner: Mariner
wolfSSL: wolfSSL
Customer Action Required: Yes
Debian
CVE-2026-3547: wolfssl - Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 a...
vendor_debian·2026·CVSS 7.5
CVE-2026-3547 [HIGH] CVE-2026-3547: wolfssl - Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 a...
Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is enabled for these 3rd party compatibility features: enable-apachehttpd, enable-bind, enable-curl, enable-haproxy, enable-hitch, enable-lighty, enable-jni, enable-nginx, enable-quic.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.9.0-0.1)
sid: resolved (fixed in 5.9.0-0.1)
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-4395 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-4395 [HIGH] CVE-2026-4395 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4395 :
wolfSSL vulnerability analysis and mitigation
Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-controlled data past the bounds of the pubkey_raw buffer via a crafted oversized EC public key point. The WOLFSSL_KCAPI_ECC code path copies the input to key->pubkey_raw (132 bytes) using XMEMCPY without a bounds check, unlike the ATECC code path which includes a length validation. This can be triggered during TLS key exchange when a malicious peer sends a crafted ECPoint in ServerKeyExchange.
Source : NVD
## 1.3
Score
Published March 19, 2026
Severity LOW
CNA Score 1.3
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/
Wiz
CVE-2026-3580 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-3580 [HIGH] CVE-2026-3580 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3580 :
wolfSSL vulnerability analysis and mitigation
In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by GCC when targeting RISC-V RV32I with -O3. This transformation breaks the side-channel resistance of ECC scalar multiplication, potentially allowing a local attacker to recover secret keys via timing analysis.
Source : NVD
## 2.1
Score
Published March 19, 2026
Severity LOW
CNA Score 2.1
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:wolfssl:wolfssl
wolfssl
Sources
Debian 11, 12, 13 Sever
Wiz
CVE-2026-3549 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-3549 [HIGH] CVE-2026-3549 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3549 :
wolfSSL vulnerability analysis and mitigation
Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.
Source : NVD
## 8.3
Score
Published March 19, 2026
Severity HIGH
CNA Score 8.3
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
wolfssl
cpe:2.3:a:wolfssl:wolfssl
Sources
Debian 11 Severity CRITICAL No Fix Added at: Mar 20, 2026
Debian
Wiz
CVE-2026-0819 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.2
CVE-2026-0819 [LOW] CVE-2026-0819 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0819 :
wolfSSL vulnerability analysis and mitigation
A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSignedAttributes(), when adding custom signed attributes, the code passes an incorrect capacity value (esd->signedAttribsCount) to EncodeAttributes() instead of the remaining available space in the fixed-size signedAttribs[7] array. When an application sets pkcs7->signedAttribsSz to a value greater than MAX_SIGNED_ATTRIBS_SZ (default 7) minus the number of default attributes already added, EncodeAttributes() writes beyond the array bounds, causing stack memory corruption. In WOLFSSL_SMALL_STACK builds, this becomes heap corruption. Exploitation requires an application that allows untrusted input to control the
Wiz
CVE-2026-3229 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 1.2
CVE-2026-3229 [LOW] CVE-2026-3229 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3229 :
wolfSSL vulnerability analysis and mitigation
An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when certificate data was written out of bounds of an insufficiently sized certificate buffer. wolfssl_add_to_chain is called by these API: wolfSSL_CTX_add_extra_chain_cert, wolfSSL_CTX_add1_chain_cert, wolfSSL_add0_chain_cert. These API are enabled for 3rd party compatibility features: enable-opensslall, enable-opensslextra, enable-lighty, enable-stunnel, enable-nginx, enable-haproxy. This issue is not remotely exploitable, and would require that the application context loading certificates is compromised.
Source : NVD
## 1.2
Score
Published March 19, 2026
Severity LOW
CNA Score 1.2
Affected Technolog
Wiz
CVE-2026-2646 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.0
CVE-2026-2646 [MEDIUM] CVE-2026-2646 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2646 :
wolfSSL vulnerability analysis and mitigation
A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certificate and session id lengths are read from an untrusted input without bounds validation, allowing an attacker to overflow fixed-size buffers and corrupt heap memory. A maliciously crafted session would need to be loaded from an external source to trigger this vulnerability. Internal sessions were not vulnerable.
Source : NVD
## 5
Score
Published March 19, 2026
Severity MEDIUM
CNA Score 5.0
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS)
Wiz
CVE-2026-3849 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-3849 [HIGH] CVE-2026-3849 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3849 :
wolfSSL vulnerability analysis and mitigation
Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciously crafted ECH config could cause a stack buffer overflow on the client side, leading to potential remote execution and client program crash. This could be exploited by a malicious TLS server supporting ECH. Note that ECH is off by default, and is only enabled with enable-ech.
Source : NVD
## 6.9
Score
Published March 19, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 41.9
Exploitation Prob
Wiz
CVE-2025-13912 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 1.0
CVE-2025-13912 [LOW] CVE-2025-13912 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13912 :
wolfSSL vulnerability analysis and mitigation
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.
Source : NVD
## 1
Score
Published December 11, 2025
Severity LOW
CNA Score 1.0
Affected Technologies
wolfSSL
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:wolfssl:wolfssl
wolfssl
Sources
NVD
CBL-Mariner 2.0 Severity LOW Has Fix Added at: Jan 01,
Wiz
CVE-2026-4159 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-4159 [HIGH] CVE-2026-4159 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4159 :
wolfSSL vulnerability analysis and mitigation
1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_DecodeEnvelopedData could be triggered by a crafted CMS EnvelopedData message with zero-length encrypted content. Note that PKCS7 support is disabled by default.
Source : NVD
## 1.2
Score
Published March 19, 2026
Severity LOW
CNA Score 1.2
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:wolfssl:wolfssl
wolfssl
Sources
Wiz
CVE-2026-3503 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-3503 [MEDIUM] CVE-2026-3503 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3503 :
wolfSSL vulnerability analysis and mitigation
Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M microcontrollers allows a physical attacker to compromise key material and/or cryptographic outcomes via induced transient faults that corrupt or redirect seed/pointer values during Keccak-based expansion.
This issue affects wolfSSL (wolfCrypt): commit hash d86575c766e6e67ef93545fa69c04d6eb49400c6.
Source : NVD
## 4.3
Score
Published March 19, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.5
Exploitation Probability (EPSS) N/A
Affected
Wiz
CVE-2026-2645 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-2645 [MEDIUM] CVE-2026-2645 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2645 :
wolfSSL vulnerability analysis and mitigation
In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could incorrectly accept the CertificateVerify message before the ClientKeyExchange message had been received. This issue affects wolfSSL before 5.8.4 (wolfSSL 5.8.2 and earlier is vulnerable, 5.8.4 is not vulnerable). In 5.8.4 wolfSSL would detect the issue later in the handshake. 5.9.0 was further hardened to catch the issue earlier in the handshake.
Source : NVD
## 5.5
Score
Published March 19, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8
Wiz
CVE-2026-3230 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 1.2
CVE-2026-3230 [LOW] CVE-2026-3230 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3230 :
wolfSSL vulnerability analysis and mitigation
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resulting in derivation of predictable traffic secrets from (EC)DHE shared secret. This issue does not affect the client's authentication of the server during TLS handshakes.
Source : NVD
## 1.2
Score
Published March 19, 2026
Severity LOW
CNA Score 1.2
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19
Wiz
CVE-2026-3547 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-3547 [HIGH] CVE-2026-3547 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3547 :
wolfSSL vulnerability analysis and mitigation
Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is enabled for these 3rd party compatibility features: enable-apachehttpd, enable-bind, enable-curl, enable-haproxy, enable-hitch, enable-lighty, enable-jni, enable-nginx, enable-quic.
Source : NVD
## 7.5
Score
Published March 19, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Releas
Wiz
CVE-2026-3548 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-3548 [HIGH] CVE-2026-3548 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3548 :
wolfSSL vulnerability analysis and mitigation
Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when improperly storing the CRL number as a hexadecimal string, and a stack-based overflow for sufficiently sized CRL numbers. With appropriately crafted CRLs, either of these out of bound writes could be triggered. Note this only affects builds that specifically enable CRL support, and the user would need to load a CRL from an untrusted source.
Source : NVD
## 7.2
Score
Published March 19, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Perce
Wiz
CVE-2026-1005 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.1
CVE-2026-1005 [LOW] CVE-2026-1005 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1005 :
wolfSSL vulnerability analysis and mitigation
Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large value that is passed to AEAD decryption routines, causing heap buffer overflow and a crash. An unauthenticated attacker can trigger this remotely via malformed TLS Application Data records.
Source : NVD
## 2.1
Score
Published March 19, 2026
Severity LOW
CNA Score 2.1
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Perc
Wiz
CVE-2026-3579 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-3579 [HIGH] CVE-2026-3579 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3579 :
wolfSSL vulnerability analysis and mitigation
wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The compiler-inserted __muldi3 subroutine executes in variable time based on operand values. This affects multiple SP math functions (sp_256_mul_9, sp_256_sqr_9, etc.), leading to a timing side-channel that may expose sensitive cryptographic data.
Source : NVD
## 2.1
Score
Published March 19, 2026
Severity LOW
CNA Score 2.1
Affected Technologies
wolfSSL
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
wolfssl
cpe:2.3:a:wolfssl:wolfss
2026-03-19
Published