#VU125932 Heap-based buffer overflow in wolfSSL - CVE-2026-5503
Published: April 14, 2026
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in TLSX_EchChangeSNI and TLSX_SNI_Write when processing ECH SNI state changes. A remote attacker can supply an attacker-controlled publicName to cause a denial of service or execute arbitrary code.
The overflow occurs when no inner SNI is configured.