Back to search
CVE-2026-5507
Published: Apr 9, 2026
Modified: Apr 14, 2026
PUBLISHED
Description
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the cache and for the application to call specific session restore APIs.
| Vendor | Product | Versions |
|---|---|---|
wolfSSL | wolfSSL | affected 0 - <= 5.9.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now