CVE-2026-3548
HIGHBuffer overflow in CRL number parsing in wolfSSL
Title source: cnaDescription
Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when improperly storing the CRL number as a hexadecimal string, and a stack-based overflow for sufficiently sized CRL numbers. With appropriately crafted CRLs, either of these out of bound writes could be triggered. Note this only affects builds that specifically enable CRL support, and the user would need to load a CRL from an untrusted source.
Scores
CVSS v4
7.2
EPSS
0.0002
EPSS Percentile
6.2%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Details
CWE
CWE-122
CWE-787
Status
published
Products (1)
wolfSSL/wolfSSL
< 5.9.0
Published
Mar 19, 2026
Tracked Since
Mar 19, 2026