wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation
Fixed in: wolfSSL 5.9.0
patched
details
Finding IDs
F-WOLFSSL-ALPN-001
CVE
CVE-2026-3547
GHSA
GHSA-f377-557w-vjgv
Status
patched
Fixed in
wolfSSL 5.9.0
Recorded credit
thanks to Oleh Konko (1seal) for the report (wolfSSL v5.9.0-stable release note)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE registry state
PUBLISHED
CVE state checked
F-WOLFSSL-ALPN-001: Memory safety. The published advisory describes an out-of-bounds read in ALPN list parsing. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.