CVE-2026-3548Disclosure(wolfssl / wolfssl)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when improperly storing the CRL number as a hexadecimal string, and a stack-based overflow for sufficiently sized CRL numbers. With appropriately crafted CRLs, either of these out of bound writes could be triggered. Note this only affects builds that specifically enable CRL support, and the user would need to load a CRL from an untrusted source.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-19: 2Mentions · 2026-03-23: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-23: 103-1903-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-192
Disclosure2
2026-03-231
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3548 Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when improperly storing the CRL… https://www.cve.org/CVERecord?id=CVE-2026-3548

    Post summary

    The passage announces two heap‑based buffer overflow vulnerabilities in the wolfSSL CRL parser.

    0000083
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3548 Buffer Overflow Vulnerabilities in wolfSSL CRL Parser Enabling Arbitrary Write https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3548

    Post summary

    The post announces CVE-2026-3548, a buffer overflow in wolfSSL’s CRL parser that leads to arbitrary write, with no PoC, exploit code, or patch details provided.

    0000046
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3548 - Buffer overflow in CRL number parsing in wolfSSL Intel Report: https://ift.tt/GI9nXiL

    Post summary

    An alert reports CVE-2026-3548 as a buffer overflow in wolfSSL's CRL number parsing, with an Intel report cited but no PoC, exploit, or patch details.

    0000034
    336 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more