Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
2.3
CVE-2026-7531: TLS 1.3 KeyShare Handling Error in OpenSSL
CVE-2026-7531
Summary
A specific type of malicious server can cause OpenSSL to use memory that has already been freed, potentially leading to security issues. This is related to a previously fixed issue and requires further attention. To mitigate this, update to the latest version of OpenSSL.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wolfssl | wolfssl |
>= 5.8.0, < 5.9.2 cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
Original title
Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can sti...
Original description
Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can still trigger the error cleanup path to operate on freed memory.
nvd CVSS4.0
2.3
Vulnerability type
CWE-416
Use After Free
Published: 25 Jun 2026 · Updated: 23 Jul 2026 · First seen: 25 Jun 2026