CVE-2026-6681

Severity CVSS v4.0:
LOW
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
25/06/2026
Last modified:
27/06/2026

Description

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* 3.10.0 (including) 5.9.1 (excluding)