CVE-2026-57223

high

Description

The vulnerability exists due to an integer overflow condition inside the TLS certificate parsing engine. An unauthenticated remote attacker can send an excessively long or malformed Extensions field within a Client Hello packet, forcing an incorrect memory allocation size that results in a process-terminating Denial of Service (DoS).

Details

Source: Mitre, NVD

Published: 2026-07-23

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High