VYPR
Medium severity5.3NVD Advisory· Published Jun 25, 2026· Updated Jul 1, 2026

CVE-2026-6678

CVE-2026-6678

Description

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

Affected products

3
  • WolfSSL/Wolfsslinferred3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*range: >=3.15.5,<5.9.2
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

1