CVE-2026-5393: wolfSSL
Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on crafted input. This can only occur when --enable-experimental and --enable-dual-alg-certs is used when building wolfSSL.
Affected products
- wolfSSL wolfSSL: before 5.9.1 (fixed in 5.9.1)
Published 2026-04-10. Last modified 2026-06-17.