An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when certificate data was written out of bounds of an insufficiently sized certificate buffer. wolfssl_add_to_chain is called by these API: wolfSSL_CTX_add_extra_chain_cert, wolfSSL_CTX_add1_chain_cert, wolfSSL_add0_chain_cert. These API are enabled for 3rd party compatibility features: enable-opensslall, enable-opensslextra, enable-lighty, enable-stunnel, enable-nginx, enable-haproxy. This issue is not remotely exploitable, and would require that the application context loading certificates is compromised.
{
"license": "CC-BY-4.0",
"sources": [
{
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3229",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-3229",
"published": "2026-03-19T21:17:12.330Z",
"id": "CVE-2026-3229",
"imported": "2026-07-17T22:27:57.386Z",
"modified": "2026-06-17T10:43:15.413Z",
"database_specific": {
"status": "Analyzed"
}
}
]
}