Junglewise Threat Intelligence

CVE-2026-5448: wolfSSL heap overflow in X.509 date parsing compatibility layer

CVE-2026-5448 · Severity: medium · CVSS 4.3 · Published 2026-04-10

Technologies: Wolfssl. Vendors: Wolfssl.

Executive brief

wolfSSL is a security library used to provide encrypted communications for applications and devices. A vulnerability in how it handles security certificates could allow an attacker to cause a crash or service disruption by providing a specially crafted certificate. This issue specifically affects applications that manually inspect certificate expiration dates using certain library functions, though it does not impact standard web traffic (TLS) or automatic certificate verification.

Technical details

A heap-based buffer overflow (CWE-122) exists in wolfSSL_X509_notAfter and wolfSSL_X509_notBefore within the OpenSSL compatibility layer. The vulnerability is caused by insufficient bounds checking when copying date fields from a decoded certificate into the internal WOLFSSL_X509 structure. Specifically, the internal logic allowed date lengths up to 32 bytes (MAX_DATE_SZ), while the destination buffer pattern expected a maximum of 30 bytes to accommodate a 2-byte offset. An attacker can exploit this by providing a crafted X.509 certificate to an application that directly invokes these getter APIs. This does not affect standard TLS handshakes or internal certificate verification. The issue was addressed in wolfSSL version 5.9.1 by adding proper bounds checks in both the getter and setter functions.

Affected products

  • wolfSSL wolfSSL versions up to (excluding) 5.9.1

Timeline

  • 2026-03-25: other: Initial fix submitted via GitHub Pull Request
  • 2026-04-02: patched: Fix merged into master branch
  • 2026-04-09: advisory: CVE-2026-5448 published by wolfSSL
  • 2026-04-29: other: NVD analysis and CPE information added

References

Related threats