#VU125923 Improper Verification of Cryptographic Signature in wolfSSL - CVE-2026-5194
Published: April 14, 2026
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to reduce the security of certificate-based authentication.
The vulnerability exists due to improper cryptographic signature verification in signature verification functions when verifying certificate signatures. A remote attacker can present certificates with digests smaller than allowed to reduce the security of certificate-based authentication.
The issue affects multiple signature algorithms, including ECDSA/ECC, DSA, ML-DSA, ED25519, and ED448.