PT-2026-52587 · Wolfssl · Wolfssl

·

CVE-2026-6679

·

Published

2026-06-25

·

Updated

2026-07-14

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions wolfSSL versions prior to 5.9.1
Description A heap buffer overflow occurs in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The issue stems from an integer truncation when calculating the length of the ACK record-number list, which leads to the allocation of an undersized buffer that is subsequently overrun.
Recommendations Update to version 5.9.1.

Exploit

Fix

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6679
JLSEC-2026-753

Affected Products

Wolfssl