Loading market data...
← Back to CVE feed

CVE-2026-5500

UNKNOWN View on NVD ↗

Description

wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middle can therefore truncate the mac field from 16 bytes to 1 byte, reducing the tag check from 2⁻¹²⁸ to 2⁻⁸.

Published: Apr 10, 2026 04:17 UTC Modified: Apr 10, 2026 04:17 UTC