CVE-2026-3229Disclosure(wolfssl / wolfssl)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when certificate data was written out of bounds of an insufficiently sized certificate buffer. wolfssl_add_to_chain is called by these API: wolfSSL_CTX_add_extra_chain_cert, wolfSSL_CTX_add1_chain_cert, wolfSSL_add0_chain_cert. These API are enabled for 3rd party compatibility features: enable-opensslall, enable-opensslextra, enable-lighty, enable-stunnel, enable-nginx, enable-haproxy. This issue is not remotely exploitable, and would require that the application context loading certificates is compromised.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-22: 1Mentions · 2026-03-23: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-23: 103-2203-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3229 An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when certificate data was written out of bounds of an… https://www.cve.org/CVERecord?id=CVE-2026-3229

    Post summary

    The text announces an integer overflow vulnerability in wolfSSL’s add_to_chain function that leads to heap corruption; it contains no PoC, exploit, or patch details.

    00010198
    56.8K followersView on X
  • ‘BBWriteups’@bbwriteup
    Disclosure

    "How I Accidentally Found an Integer Overflow in wolfSSL While Building a Cert Chain (CVE-2026–3229)" by MostReal #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@FufuFaf1/how-i-accidentally-found-an-integer-overflow-in-wolfssl-while-building-a-cert-chain-cve-2026-3229-b9fe453682a9

    Post summary

    The Medium article announces the discovery of an integer overflow (CVE‑2026‑3229) in wolfSSL encountered while building a certificate chain, but does not provide a PoC, exploit code, or patch information.

    0000048
    541 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more