← Vulnerability feed

Vulnerability record · CVE-2026-3547 · published 19 March 2026

CVE-2026-3547: Wolfssl out-of-bounds read vulnerability

Wolfssl · Wolfssl

Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is enabled for these 3rd party compatibility features: enable-apachehttpd, enable-bind, enable-curl, enable-haproxy, enable-hitch, enable-lighty, enable-jni, enable-nginx, enable-quic.

7.5 CVSS 3.1 High EPSS 0.44% · top 64.2% CWE-125 · Out-of-bounds read
7.5CVSS 3.1 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is enabled for these 3rd party compatibility features: enable-apachehttpd, enable-bind, enable-curl, enable-haproxy, enable-hitch, enable-lighty, enable-jni, enable-nginx, enable-quic.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/wolfSSL/wolfssl/pull/9859 Issue TrackingPatch

Track CVE-2026-3547 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-5991Wolfssl out-of-bounds read vulnerabilityIn function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the fu…EPSS 0.56%9.8CVE-2021-37155Wolfssl vulnerabilitywolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the serial number …EPSS 1.5%9.8CVE-2020-36177Wolfssl out-of-bounds write vulnerabilityRsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size.EPSS 3.5%9.8CVE-2014-2898Wolfssl out-of-bounds read vulnerabilitywolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-o…EPSS 2.8%9.8CVE-2014-2896Wolfssl out-of-bounds read vulnerabilityThe DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact an…EPSS 2.8%9.8CVE-2014-2897Wolfssl out-of-bounds read vulnerabilityThe SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote atta…EPSS 2.8%9.8CVE-2019-16748Wolfssl out-of-bounds read vulnerabilityIn wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there…EPSS 1.2%9.8CVE-2019-15651Wolfssl out-of-bounds read vulnerabilitywolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is misha…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2026-3547), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.