Wolfssl · Wolfssl · CVE-2026-10098
**Name of the Vulnerable Software and Affected Versions**
wolfSSL (affected versions not specified)
**Description**
A length-confusion issue exists in the `wolfSSL OCSP resp find status()` function. The lookup process compares serial-number bytes without verifying that the two serial numbers are of equal length. Consequently, a SingleResponse from the same issuer, where the serial number is a prefix of the target serial number, can be incorrectly reported as the revocation status of a different certificate.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.