CVE-2026-6681

MEDIUM

PKCS#7 decode ignores caller output buffer size, writing past buffer bounds

Title source: cna
STIX 2.1

Description

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

Scores

CVSS v3 5.3
EPSS 0.0026
EPSS Percentile 17.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-120 CWE-787
Status published
Products (2)
wolfSSL/wolfSSL 3.10.0 - 5.9.0
wolfssl/wolfssl 3.10.0 - 5.9.1
Published Jun 25, 2026
Tracked Since Jun 26, 2026