In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging).
{
"license": "CC-BY-4.0",
"sources": [
{
"database_specific": {
"status": "Modified"
},
"id": "CVE-2023-6936",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6936",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-6936",
"published": "2024-02-20T22:15:08.197Z",
"modified": "2026-06-17T06:51:43.160Z",
"imported": "2026-07-17T22:23:41.884Z"
},
{
"id": "GHSA-cwpg-8775-j56v",
"html_url": "https://github.com/advisories/GHSA-cwpg-8775-j56v",
"url": "https://api.github.com/advisories/GHSA-cwpg-8775-j56v",
"published": "2024-02-21T00:31:31Z",
"modified": "2025-03-26T18:31:48Z",
"imported": "2026-07-17T22:23:42.047Z"
},
{
"id": "EUVD-2023-59134",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59134",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2023-59134",
"published": "2024-02-20T21:52:02Z",
"modified": "2025-03-26T16:28:30Z",
"imported": "2026-07-17T22:23:50.518Z"
}
]
}