CVE-2017-8854: wolfSSL

High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.

wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow triggered by a malformed temporary DH file.

Affected products

  • wolfSSL wolfSSL: up to and including 3.10.0a

Published 2017-05-09. Last modified 2026-06-17.