wolfSSL Dual-Algorithm CertificateVerify Out-of-Bounds Read Vulnerability

Vulnerability

An out-of-bounds read vulnerability has been identified in wolfSSL when processing dual-algorithm CertificateVerify messages. This issue arises from crafted input and can only be exploited if wolfSSL is built with the --enable-experimental and --enable-dual-alg-certs options.

Impact

Exploitation of this vulnerability leads to an out-of-bounds read, which can potentially be used to read sensitive data or cause a denial-of-service condition.

Added: Apr 10, 2026, 2:04 AM
Updated: Apr 10, 2026, 2:04 AM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
0.6
exploitability
4.7
remediation
8.3
relevance
5.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.