Loading market data...
← Back to CVE feed

CVE-2026-5504

UNKNOWN View on NVD ↗

Description

A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In previous versions of wolfSSL the interior padding bytes are not validated.

Published: Apr 09, 2026 23:17 UTC Modified: Apr 09, 2026 23:17 UTC