CVE-2026-2646Disclosure(wolfssl / wolfssl)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certificate and session id lengths are read from an untrusted input without bounds validation, allowing an attacker to overflow fixed-size buffers and corrupt heap memory. A maliciously crafted session would need to be loaded from an external source to trigger this vulnerability. Internal sessions were not vulnerable.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-19); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 103-1903-2003-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Jonathan Bar Or (JBO) 🇮🇱🇺🇸🇺🇦@yo_yo_yo_jbo
    Disclosure

    My remote session deserialization heap OOB in wolfSSL is finally public (CVE-2026-2646). Thanks so much wolfSSL for the collaboration! Would folks be interested in a short writeup?

    Post summary

    The post announces that CVE‑2026‑2646, a remote session deserialization out‑of‑bounds issue in wolfSSL, has been publicly disclosed and invites a brief write‑up.

    53048124.4K
    4.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2646 A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certificate and… https://www.cve.org/CVERecord?id=CVE-2026-2646

    Post summary

    The tweet announces the discovery of a heap‑buffer‑overflow vulnerability in wolfSSL’s session deserialization code when SESSION_CERTS is enabled.

    0000064
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2646 - Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function Intel Report: https://ift.tt/enAluI2

    Post summary

    A warning has been issued for CVE-2026-2646, describing a heap buffer overflow in the wolfSSL session parsing function, with no evidence of exploitation or available patch.

    0000037
    336 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more