Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://github.com/wolfSSL/wolfssl/pull/9817 |
Configurations
No configuration.
History
19 Mar 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-19 21:17
Updated : 2026-03-20 13:39
NVD link : CVE-2026-3549
Mitre link : CVE-2026-3549
CVE.ORG link : CVE-2026-3549
JSON object : View
Products Affected
No product.
CWE
CWE-122
Heap-based Buffer Overflow
