CVE-2019-18840: wolfSSL

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.

Affected products

  • wolfSSL wolfSSL: from 4.1.0, up to and including 4.2.0c

Published 2019-11-09. Last modified 2026-06-17.