MEDIUM
CVE-2026-6681
CVSS
5.3
Description
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.
Weakness (CWE)
CWE-120
Classic Buffer Overflow
CWE-787
Out-of-bounds Write
EPSS Score
0.38%
Probability of exploitation in next 30 days
31.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.