CVE-2026-5393: wolfSSL

Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on crafted input. This can only occur when --enable-experimental and --enable-dual-alg-certs is used when building wolfSSL.

Affected products

  • wolfSSL wolfSSL: before 5.9.1 (fixed in 5.9.1)

Published 2026-04-10. Last modified 2026-06-17.