CVE-2026-7531: Use-after-free in PQC hybrid key-share handling
Published Jun 25, 2026
·Updated
Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can still trigger the error cleanup path to operate on freed memory.
Affected Software
2 affected components
PQ
wolfSSL wolfssl>=5.8.0<5.9.2
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·08:01 PM
Data Sourced
via MITRE·08:01 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-7531?
CVE-2026-7531 has a severity rating of low with a CVSS score of 4.0.
2
What is CVE-2026-7531?
CVE-2026-7531 is a use-after-free vulnerability in PQC hybrid key-share handling that allows a malicious TLS 1.3 server to exploit freed memory.
3
How do I fix CVE-2026-7531?
To fix CVE-2026-7531, apply the available patch from the wolfSSL repository.
4
What software is affected by CVE-2026-7531?
CVE-2026-7531 affects the wolfSSL library used for PQC (Post-Quantum Cryptography) implementations.
5
Is there a known workaround for CVE-2026-7531?
There are no known workarounds for CVE-2026-7531; the recommended action is to apply the patch.