A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certificate and session id lengths are read from an untrusted input without bounds validation, allowing an attacker to overflow fixed-size buffers and corrupt heap memory. A maliciously crafted session would need to be loaded from an external source to trigger this vulnerability. Internal sessions were not vulnerable.
{
"license": "CC-BY-4.0",
"sources": [
{
"database_specific": {
"status": "Analyzed"
},
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2646",
"id": "CVE-2026-2646",
"imported": "2026-07-17T22:27:48.628Z",
"modified": "2026-06-17T10:31:27.500Z",
"published": "2026-03-19T18:16:22.223Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-2646"
},
{
"html_url": "https://github.com/advisories/GHSA-24vq-qfc5-qrmj",
"id": "GHSA-24vq-qfc5-qrmj",
"imported": "2026-07-17T22:27:48.795Z",
"modified": "2026-04-29T21:31:20Z",
"published": "2026-03-19T18:31:19Z",
"url": "https://api.github.com/advisories/GHSA-24vq-qfc5-qrmj"
},
{
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-13137",
"id": "EUVD-2026-13137",
"imported": "2026-07-17T22:27:57.193Z",
"modified": "2026-03-19T17:44:09Z",
"published": "2026-03-19T17:25:42Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-13137"
}
]
}