Critical severity9.1OSV Advisory· Published Jun 25, 2026· Updated Jun 26, 2026
CVE-2026-6094
CVE-2026-6094
Description
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/wolfSSL/wolfssl/pull/10128nvdIssue TrackingPatch
- www.wolfssl.com/docs/security-vulnerabilities/nvdVendor Advisory
News mentions
0No linked articles in our index yet.