
The bug classes don't care how new the primitive is — fresh parsing and length-handling code in C reintroduces them every time. From my audits this year: wolfSSL ECH config parser (stack overflow, CVE-2026-3849), GnuTLS DTLS fragment reassembly (heap overflow, CVE-2026-33846), Mbed TLS FFDH export (heap overflow, CVE-2026-34875). PQ rollout means a lot of fresh C. The prediction sounds right.
Post summary
Audit results reveal three new CVEs in TLS libraries—each causing either a stack or heap overflow—without discussion of patches or exploitation evidence.


