CVE-2026-3547 is an out-of-bounds read vulnerability affecting wolfSSL versions 5.8.4 and earlier, occurring during ALPN parsing when ALPN is enabled. This High severity flaw (CVSS 7.5) allows an unauthenticated, remote attacker to cause a denial-of-service by sending a crafted ALPN protocol list, leading to a process crash. Although ALPN is disabled by default, it is automatically enabled for several third-party compatibility features, broadening the potential attack surface. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion beyond a single mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 5.9.0CPE match | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* | ||
< 5.9.0CPE matchmatch criteria | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.