CVE-2026-4159

Severity CVSS v4.0:
LOW
Type:
CWE-125 Out-of-bounds Read
Publication date:
19/03/2026
Last modified:
29/04/2026

Description

1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_DecodeEnvelopedData could be triggered by a crafted CMS EnvelopedData message with zero-length encrypted content. Note that PKCS7 support is disabled by default.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* 5.9.0 (excluding)


References to Advisories, Solutions, and Tools