Junglewise Threat Intelligence

CVE-2026-5188: wolfSSL integer underflow in X.509 SAN extension parsing

CVE-2026-5188 · Severity: high · CVSS 8.1 · Published 2026-04-10

Technologies: Wolfssl. Vendors: Wolfssl.

Executive brief

wolfSSL is a security library used by applications to establish secure encrypted connections. A vulnerability in how it processes digital certificates could allow an attacker to provide a specially crafted certificate that causes the software to malfunction. This could lead to a service outage or potentially allow an attacker to access sensitive information, though it only affects systems using a specific, non-default configuration.

Technical details

An integer underflow exists in the `DecodeAltNames()` function within `wolfcrypt/src/asn.c`. When parsing the Subject Alternative Name (SAN) extension of an X.509 certificate, a malformed certificate can specify an entry length larger than the enclosing sequence. This causes the internal length counter to wrap (underflow) during the `length -= strLen` operation. The vulnerability is specifically located in the non-template ASN.1 parsing path, which is enabled via the `--enable-asn=original` flag and is off by default. An attacker can exploit this by presenting a malicious certificate during a TLS handshake or certificate validation process, potentially leading to a denial of service or information disclosure. The issue was addressed in version 5.9.1 by adding proper bounds checks before length subtraction.

Affected products

  • wolfSSL wolfSSL up to (excluding) 5.9.1

Timeline

  • 2026-03-20: patched: Fix merged into master branch via pull request 10024
  • 2026-04-10: disclosed: CVE-2026-5188 published

References

Related threats