CVE-2026-5504

A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In previous versions of wolfSSL the interior padding bytes are not validated.
References
Link Resource
https://github.com/wolfSSL/wolfssl/pull/10088 Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

History

29 Apr 2026, 14:06

Type Values Removed Values Added
First Time Wolfssl
Wolfssl wolfssl
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://github.com/wolfSSL/wolfssl/pull/10088 - () https://github.com/wolfSSL/wolfssl/pull/10088 - Issue Tracking, Patch
CPE cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

09 Apr 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 23:17

Updated : 2026-04-29 14:06


NVD link : CVE-2026-5504

Mitre link : CVE-2026-5504

CVE.ORG link : CVE-2026-5504


JSON object : View

Products Affected

wolfssl

  • wolfssl
CWE
CWE-354

Improper Validation of Integrity Check Value