Out-of-bounds Write Vulnerability in wolfSSL Library
CVE-2026-6325

2LOW

Key Information:

Vendor

Wolfssl

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-6325?

An out-of-bounds write vulnerability exists in the wolfSSL library's SetSuitesHashSigAlgo function, triggered when processing oversized signature algorithms lists. This flaw permits data to be written beyond the intended buffer limits, potentially leading to unexpected behavior, data corruption, or even remote code execution under specific conditions. It is crucial for developers utilizing this cryptographic library to implement the latest patches to mitigate risks associated with this vulnerability.

Affected Version(s)

wolfSSL 4.8.0 <= 5.9.1

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Arya Arjuna Habibullah (Pelioro)
.