CVE-2023-6936: wolfSSL
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging).
Affected products
- wolfSSL wolfSSL: before 5.6.6 (fixed in 5.6.6)
Published 2024-02-20. Last modified 2026-06-17.