CVE-2026-5264: DTLS 1.3 ACK heap buffer overflow
Published Apr 9, 2026
·Updated
Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer overflow.
Affected Software
1 affected component
wolfSSL wolfssl<5.9.1
Remediation
Patch Available
Event History
Apr 9, 2026
CVE Published
via MITRE·09:43 PM
Data Sourced
via MITRE·09:43 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-5264?
CVE-2026-5264 has a high severity rating of 8.3 on the CVSS scale.
2
How do I fix CVE-2026-5264?
The recommended fix for CVE-2026-5264 is to apply the available patch from wolfSSL.
3
What are the potential impacts of CVE-2026-5264?
CVE-2026-5264 can lead to a heap buffer overflow, allowing remote attackers to exploit the vulnerability.
4
Which software is affected by CVE-2026-5264?
The vulnerable software affected by CVE-2026-5264 is wolfSSL.
5
When was CVE-2026-5264 published?
CVE-2026-5264 was published on April 9, 2026.