wolfSSL.wolfssl is vulnerable to Denial of Service (DoS)
74
High Risk
ALPN handling performs incomplete validation of the protocol list when HAVE_ALPN is enabled, allowing a crafted ALPN list to be read out of bounds and crash the process. The issue affects builds that enable ALPN, including several third-party integration presets. The fix adds validation so ALPN parsing stays within buffer bounds.
You are affected if you are using a version that falls within the vulnerable range and wolfSSL was built with ALPN enabled (HAVE_ALPN / --enable-alpn).
wolfSSL.wolfssl is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.8.4.
Upgrade the wolfSSL.wolfssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant