# wolfSSL Improper Input Validation and Integer Underflow Vulnerabilities (CVE-2026-28739, CVE-2026-25106, CVE-2026-33091)

> Cisco Talos (researcher Ankur Tyagi) disclosed three vendor-patched vulnerabilities in the wolfSSL embedded TLS/SSL library: two improper-input-validation flaws (CVE-2026-28739 / TALOS-2026-2409, CVE-2026-25106 / TALOS-2026-2410) and one integer-underflow flaw (CVE-2026-33091 / TALOS-2026-2408). All three were fixed by the vendor prior to public disclosure on 2026-07-01/02 and rolled up in a Talos blog post on 2026-07-09.

- **Published:** 2026-07-09T00:00:00Z
- **Last reviewed:** 2026-07-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1151
- **ID:** TL-2026-1151
- **Severity:** UNKNOWN
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-28739, CVE-2026-25106, CVE-2026-33091

## Description

wolfSSL is a small-footprint, portable TLS/SSL and cryptography library used across embedded systems, IoT devices, industrial and automotive controllers, medical devices, and cloud services where a lightweight secure-transport stack is required. Cisco Talos's third-party vulnerability disclosure program, through researcher Ankur Tyagi, identified and privately reported three distinct defects in the library to the vendor. Two of the three (TALOS-2026-2409 / CVE-2026-28739 and TALOS-2026-2410 / CVE-2026-25106) are classified by Talos as improper input validation issues; the source article groups both under this shared classification without further public breakdown of the specific parsing paths affected. The third (TALOS-2026-2408 / CVE-2026-33091) is classified as an integer underflow issue, a defect class in which an arithmetic subtraction on an attacker-influenced length or index value wraps below zero, typically producing an unexpectedly large unsigned value that is then used in a subsequent memory-copy or bounds calculation -- a pattern that commonly leads to heap corruption, out-of-bounds read/write, denial of service, or in the worst case remote code execution, depending on how the resulting value is consumed downstream. wolfSSL has released patches addressing all three defects; the Talos source article does not publish the affected version range, a CVSS score/vector, or any evidence of in-the-wild exploitation, so those fields are recorded as UNKNOWN/null per source-grounding requirements rather than estimated. Independent research confirms wolfSSL shipped v5.9.1 on 2026-04-08 and v5.9.2 on 2026-06-23, consistent with the Talos disclosure timeline (private vendor notification 2026-04-29, patch released 2026-06-23, public advisory 2026-07-01/02), indicating v5.9.2 is the remediated release line. Given the vulnerability classes involved -- input validation defects in a TLS library are frequently rooted in certificate/handshake parsing, and integer underflow defects in crypto/ASN.1 libraries are a recurring heap-corruption root cause (per CWE-191 advisory guidance) -- the practical risk profile for unpatched deployments is assessed as HIGH, spanning potential denial of service, memory corruption, and (for the input-validation class) possible security-control bypass in certificate/data validation logic, pending any vendor clarification of exact impact.

## MITRE ATT&CK

- T1587.004 Exploits
- T1588.005 Exploits
- T1588.006 Vulnerabilities
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1036 Masquerading
- T1211 Exploitation for Stealth
- T1557 Adversary-in-the-Middle
- T1573 Encrypted Channel
- T1499 Endpoint Denial of Service
- T1518 Software Discovery
- T1595.002 Vulnerability Scanning
- T1592.002 Software
- T1210 Exploitation of Remote Services
- T1040 Network Sniffing

## Sources

- [Vulnerability Spotlight: wolfSSL vulnerabilities disclosed](https://blog.talosintelligence.com/wolfssl-vulnerabilities/)
- [Cisco Talos Vulnerability Reports index](https://www.talosintelligence.com/vulnerability_reports)
- [Cisco Talos Zero-Day and Disclosed Vulnerability Reports](https://www.talosintelligence.com/vulnerability_info)
- [wolfSSL Security Vulnerabilities documentation](https://www.wolfssl.com/docs/security-vulnerabilities/)
- [wolfSSL Release 5.9.2 (June 23, 2026)](https://github.com/wolfSSL/wolfssl/releases/tag/v5.9.2-stable)
- [wolfSSL Release 5.9.1 (April 8, 2026)](https://github.com/wolfSSL/wolfssl/releases/tag/v5.9.1-stable)
- [Critical wolfSSL Security Vulnerabilities Expose IoT Systems](https://securityonline.info/wolfssl-security-vulnerabilities/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1151
