Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6681

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*
Версия от 3.10.0 (включая) до 5.9.1 (исключая)

EPSS

Процентиль: 17%
0.00257
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

CVSS3: 5.3
debian
около 1 месяца назад

The PKCS#7 decode path ignores the caller-supplied output buffer size ...

CVSS3: 5.3
github
около 1 месяца назад

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

EPSS

Процентиль: 17%
0.00257
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-120