MEDIUM

CVE-2026-6681

Wolfssl Wolfssl 2026-06-25 CVSS v3.1
CVSS
5.3

Description

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

Weakness (CWE)

CWE-120 Classic Buffer Overflow
CWE-787 Out-of-bounds Write

EPSS Score

0.38%
Probability of exploitation in next 30 days
31.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE