CVE-2026-40510
Severity CVSS v4.0:
LOW
Type:
CWE-121
Stack-based Buffer Overflow
Publication date:
29/05/2026
Last modified:
29/05/2026
Description
OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.
Impact
Base Score 4.0
1.00
Severity 4.0
LOW
Base Score 3.x
3.80
Severity 3.x
LOW



