Home

Description

X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing date fields from a crafted X.509 certificate via the compatibility layer API. This is only triggered when calling these two APIs directly from an application, and does not affect TLS or certificate verify operations in wolfSSL.

PUBLISHED Reserved 2026-04-02 | Published 2026-04-09 | Updated 2026-04-10 | Assigner wolfSSL




LOW: 2.3CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Green

Problem types

CWE-122 Heap-based Buffer Overflow

Product status

Default status
unaffected

Any version before 5.9.1
affected

Credits

Sunwoo Lee, Korea Institute of Energy Technology (KENTECH) finder

Seunghyun Yoon, Korea Institute of Energy Technology (KENTECH) finder

References

github.com/wolfSSL/wolfssl/pull/10071

cve.org (CVE-2026-5448)

nvd.nist.gov (CVE-2026-5448)

Download JSON