๐Ÿ” CVE Alert

CVE-2026-3549

UNKNOWN 0.0

ECH parsing heap buffer overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
15th

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

CWE CWE-122
Vendor wofssl
Product wolfssl
Published Mar 19, 2026
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for wofssl wolfssl

Be the first to know when new unknown vulnerabilities affecting wofssl wolfssl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

wofSSL / wolfSSL
0 < 5.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wolfSSL/wolfssl/pull/9817

Credits

Oleh Konko for independently reporting after internal wolfSSL findings and testing wolfSSL's fix