Heap Buffer Overflow in wolfSSL due to AuthorityKeyIdentifier Size Confusion
CVE-2026-5447
6.3MEDIUM
What is CVE-2026-5447?
A vulnerability exists in the wolfSSL library causing a heap buffer overflow when internal processing of X.509 certificates occurs. This issue arises from incorrect handling of the AuthorityKeyIdentifier size during conversion, potentially leading to memory corruption and security risks. Proper validation and handling of size parameters are essential to mitigate this vulnerability.
Affected Version(s)
wolfSSL 0 < 5.9.1
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Calif.io in collaboration with Claude and Anthropic Research
