CVE-2026-5504

A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In previous versions of wolfSSL the interior padding bytes are not validated.
CVSS

No CVSS.

Configurations

No configuration.

History

09 Apr 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 23:17

Updated : 2026-04-13 15:02


NVD link : CVE-2026-5504

Mitre link : CVE-2026-5504

CVE.ORG link : CVE-2026-5504


JSON object : View

Products Affected

No product.

CWE
CWE-354

Improper Validation of Integrity Check Value