High severity7.5NVD Advisory· Published Jun 25, 2026· Updated Jun 27, 2026
CVE-2026-6679
CVE-2026-6679
Description
A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an undersized buffer to be allocated and then overrun. This affects builds using DTLS 1.3 and wolfSSL version 5.9.0 and earlier. A fix was added to the 5.9.1 release.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/wolfSSL/wolfssl/pull/10116nvdIssue TrackingPatch
- www.wolfssl.com/docs/security-vulnerabilities/nvdVendor Advisory
News mentions
2- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- WolfSSL: Ten Vulnerabilities Disclosed Together Affecting Crypto and Certificate HandlingVypr Intelligence · Jun 26, 2026