CVE-2026-5500

wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middle can therefore truncate the mac field from 16 bytes to 1 byte, reducing the tag check from 2⁻¹²⁸ to 2⁻⁸.
References
Link Resource
https://github.com/wolfSSL/wolfssl/pull/10102 Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-10 04:17

Updated : 2026-06-17 10:59


NVD link : CVE-2026-5500

Mitre link : CVE-2026-5500

CVE.ORG link : CVE-2026-5500


JSON object : View

Products Affected

wolfssl

  • wolfssl
CWE
CWE-20

Improper Input Validation