Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2g5-52p7-mfpc

Опубликовано: 19 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 9.8

Описание

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

EPSS

Процентиль: 39%
0.00487
Низкий

8.3 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 9.8
ubuntu
5 месяцев назад

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

CVSS3: 9.8
nvd
5 месяцев назад

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

msrc
4 месяца назад

ECH parsing heap buffer overflow

CVSS3: 9.8
debian
5 месяцев назад

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ...

EPSS

Процентиль: 39%
0.00487
Низкий

8.3 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-122