Research / Finding
ECH parsing heap buffer overflow F-WOLFSSL-ECH-001
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
8.3high
ECH parsing heap buffer overflow
Fixed in: wolfSSL 5.9.0
patched
details
Finding IDs F-WOLFSSL-ECH-001 CVE CVE-2026-3549 GHSA GHSA-j2g5-52p7-mfpc Status patched Fixed in wolfSSL 5.9.0 Recorded credit thanks to Oleh Konko (1seal) for testing (wolfSSL v5.9.0-stable release note) CVSS vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVE registry state PUBLISHED CVE state checked 23 Sep 2026 F-WOLFSSL-ECH-001: Memory safety. An ECH length underflow produces a heap out-of-bounds write. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-WOLFSSL-ECH-001
Security area (1seal assessment): Memory safety. An ECH length underflow produces a heap out-of-bounds write. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .