#VU125936 Observable discrepancy in wolfSSL - CVE-2026-5504
Published: April 14, 2026
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to recover plaintext.
The vulnerability exists due to improper cryptographic validation in PKCS7 CBC decryption when processing modified ciphertext through repeated decryption queries. A remote attacker can submit modified ciphertexts to recover plaintext.
In affected versions, the interior padding bytes are not validated.