CVE-2026-3549
ECH parsing heap buffer overflow
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
15th
Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.
| CWE | CWE-122 |
| Vendor | wofssl |
| Product | wolfssl |
| Published | Mar 19, 2026 |
| Last Updated | Mar 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for wofssl wolfssl
Be the first to know when new unknown vulnerabilities affecting wofssl wolfssl are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
wofSSL / wolfSSL
0 < 5.9.0
References
Credits
Oleh Konko for independently reporting after internal wolfSSL findings and testing wolfSSL's fix