← Voltar para CVEs
CVE-2026-5504
N/ADescricao
A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In previous versions of wolfSSL the interior padding bytes are not validated.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado4/9/2026
Ultima modificacao4/13/2026
Fontenvd
Avistamentos honeypot0
Fraquezas (CWE)
CWE-354
Referencias
https://github.com/wolfSSL/wolfssl/pull/10088(facts@wolfssl.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.