CVE-2026-5460 | wolfSSL up to 5.9.0 KeyShare src/tls.c TLSX_KeyShare_ProcessPqcHybridClient use after free (Nessus ID 305910)
A vulnerability labeled as critical has been found in wolfSSL up to 5.9.0. The affected element is the function TLSX_KeyShare_ProcessPqcHybridClient of the file src/tls.c of the component KeyShare Handler. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-5460. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.