#VU125933 Out-of-bounds read in wolfSSL - CVE-2026-5392
Published: April 14, 2026
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in PKCS7_VerifySignedData() when parsing a crafted PKCS7 message. A remote attacker can provide a specially crafted PKCS7 message to cause a denial of service.
This only affects builds with PKCS7 support enabled.