{"id":"CVE-2026-15442","published":"2026-09-27T10:16:56.893","lastModified":"2026-09-28T20:47:20.760","description":"In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a partial wolfSSL_read() which is sometimes caused by a small user buffer  passed in, then called wolfSSL_shutdown for a bidirectional close and attempted to wolfSSL_read() again while the peer continues trying to send data during the shutdown it would lead to a state where a potential heap-use-after free happened.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-416"],"vendors":[],"products":[],"references":[{"url":"https://github.com/wolfSSL/wolfssl/pull/10863","tags":[]}],"exploitRefs":[{"url":"https://github.com/wolfSSL/wolfssl/pull/10863","tags":[]}],"hasPoc":true,"ai":null}