PT-2026-64464 · Julia · Wolfssl Jll

Published

2026-07-14

·

Updated

2026-07-14

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
An integer overflow vulnerability existed in the static function wolfssl add to chain, that caused heap corruption when certificate data was written out of bounds of an insufficiently sized certificate buffer. wolfssl add to chain is called by these API: wolfSSL CTX add extra chain cert, wolfSSL CTX add1 chain cert, wolfSSL add0 chain cert. These API are enabled for 3rd party compatibility features: enable-opensslall, enable-opensslextra, enable-lighty, enable-stunnel, enable-nginx, enable-haproxy. This issue is not remotely exploitable, and would require that the application context loading certificates is compromised.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-703

Affected Products

Wolfssl Jll