CVE-2026-5393

Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on crafted input. This can only occur when --enable-experimental and --enable-dual-alg-certs is used when building wolfSSL.
References
Link Resource
https://github.com/wolfSSL/wolfssl/pull/10079 Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

History

29 Apr 2026, 13:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Wolfssl
Wolfssl wolfssl
CPE cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*
References () https://github.com/wolfSSL/wolfssl/pull/10079 - () https://github.com/wolfSSL/wolfssl/pull/10079 - Issue Tracking, Patch

10 Apr 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-10 00:16

Updated : 2026-04-29 13:58


NVD link : CVE-2026-5393

Mitre link : CVE-2026-5393

CVE.ORG link : CVE-2026-5393


JSON object : View

Products Affected

wolfssl

  • wolfssl
CWE
CWE-125

Out-of-bounds Read