Back to search
CVE-2026-5392
Published: Apr 9, 2026
Modified: Apr 10, 2026
PUBLISHED
Description
Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bounds check is in the indefinite-length end-of-content verification loop in PKCS7_VerifySignedData().
| Vendor | Product | Versions |
|---|---|---|
wolfSSL | wolfSSL | affected 0 - < 5.9.1 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now