CVE-2026-3849Disclosure(wolfssl / wolfssl)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciously crafted ECH config could cause a stack buffer overflow on the client side, leading to potential remote execution and client program crash. This could be exploited by a malicious TLS server supporting ECH. Note that ECH is off by default, and is only enabled with enable-ech.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-23); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-23: 2Mentions · 2026-07-02: 1Technical Details · 2026-03-23: 2Technical Details · 2026-07-02: 103-2307-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-232
Disclosure2
2026-07-021
Disclosure1
Full discourse3 posts
  • Haruto Kimura@harutosec
    Disclosure

    The bug classes don't care how new the primitive is — fresh parsing and length-handling code in C reintroduces them every time. From my audits this year: wolfSSL ECH config parser (stack overflow, CVE-2026-3849), GnuTLS DTLS fragment reassembly (heap overflow, CVE-2026-33846), Mbed TLS FFDH export (heap overflow, CVE-2026-34875). PQ rollout means a lot of fresh C. The prediction sounds right.

    Post summary

    Audit results reveal three new CVEs in TLS libraries—each causing either a stack or heap overflow—without discussion of patches or exploitation evidence.

    00011161
    20 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3849 Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciou… https://www.cve.org/CVERecord?id=CVE-2026-3849 ----- Traducción: CVE-2026-3849 Des… http://infoflow.cloud`

    Post summary

    CVE‑2026‑3849 is a newly disclosed stack buffer overflow vulnerability in wolfSSL 5.8.4 ECH caused by oversized ECH configurations.

    0000014
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3849 Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciou… https://www.cve.org/CVERecord?id=CVE-2026-3849

    Post summary

    The text announces a stack buffer overflow vulnerability (CVE‑2026‑3849) in wolfSSL’s ECH support via an oversized configuration, offering technical details but no PoC, patch, or exploitation evidence.

    00000124
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more