← Retour à la recherche de CVE

CVE-2026-5504

wolfSSL

Description

A padding oracle exists in wolfSSL-s PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In previous versions of wolfSSL the interior padding bytes are not validated.

CVSS 6.3EPSS 0.11100000000000002%Risque 0.64
Voir la source
Publication
2026-04-09 23:17:01
Versions concernées
unknown
Type
Core software
Vecteur
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X