Home

Description

Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer overflow.

PUBLISHED Reserved 2026-03-31 | Published 2026-04-09 | Updated 2026-04-10 | Assigner wolfSSL




HIGH: 8.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-122 Heap-based Buffer Overflow

Product status

Default status
unaffected

Any version before 5.9.1
affected

Credits

Sunwoo Lee, Korea Institute of Energy Technology (KENTECH) finder

Seunghyun Yoon, Korea Institute of Energy Technology (KENTECH) finder

References

github.com/wolfssl/wolfssl/pull/10076

cve.org (CVE-2026-5264)

nvd.nist.gov (CVE-2026-5264)

Download JSON