CVE-2026-5507
Severity CVSS v4.0:
MEDIUM
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
09/04/2026
Last modified:
29/04/2026
Description
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the cache and for the application to call specific session restore APIs.
Impact
Base Score 4.0
4.10
Severity 4.0
MEDIUM
Base Score 3.x
4.00
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* | 5.9.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



