Use-after-free in wolfSSL - CVE-2026-15442
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a heap-use-after-free.
The vulnerability exists due to a heap-use-after-free in the TLS shutdown state handling when an application reads data after a partial wolfSSL_read() and bidirectional wolfSSL_shutdown(). A remote attacker can continue sending data during shutdown to cause a heap-use-after-free.
The condition requires a partial read, which can occur when the application uses a small user buffer.