CVE-2026-5264 is a heap buffer overflow vulnerability in DTLS 1.3 ACK message processing that allows a remote attacker to trigger a crash or potentially execute arbitrary code by sending a specially crafted ACK message. The specific affected products are not detailed in the available data, but this vulnerability impacts systems utilizing DTLS 1.3 protocol implementations. The vulnerability presents a moderate risk with a FAUCET Risk Score of 50.0 out of 100, though precise CVSS metrics are not yet available. The attack requires only network access with no special privileges or user interaction, making it remotely exploitable. However, the extremely low EPSS score of 0.002410000 indicates this vulnerability is currently ranked lower in probability of exploitation compared to the vast majority of known CVEs. Regarding exploitation status, there is no evidence of active real-world exploitation, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. No publicly available exploit code has been documented in the accessible vulnerability databases at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 5.9.1CPE match | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* | ||
< 5.9.1CPE matchmatch criteria | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.