Sploitus

CVE-2026-3549

No indexed exploits for CVE-2026-3549 yet

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

Affected products
Wolfssl
Wolfssl
< 5.9.0
CVSS 3.1
9.8 CRITICAL
EPSS
0.5% (39th percentile)
Weakness
CWE-122
NVD status
Analyzed
Published
2026-03-19
CVE-2026-3549 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-3549 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-3549 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.