2.3
/ 10
LOW
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Description
Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bounds check is in the indefinite-length end-of-content verification loop in PKCS7_VerifySignedData().
Basic Information
ID
CVE-2026-5392
Source
wolfSSL
Published
Apr 9, 2026 at 23:10
Modified
Apr 10, 2026 at 14:08
Affected Product
Vendor
wolfSSL
Product
wolfSSL
Affected Versions
wolfSSL wolfSSL 0