CVE-2026-6094: Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData
Published Jun 25, 2026
·Updated
Heap buffer overread in wcPKCS7DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.
Affected Software
2 affected components
wolfSSL wc_PKCS7_DecodeEnvelopedData
wolfSSL wolfssl>=5.8.0<5.9.2
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-6094?
CVE-2026-6094 has a medium severity level with a CVSS score of 6.3.
2
What software is affected by CVE-2026-6094?
CVE-2026-6094 affects the wolfSSL library, specifically the wc_PKCS7_DecodeEnvelopedData function.
3
How do I fix CVE-2026-6094?
To fix CVE-2026-6094, you need to apply the available patch from the wolfSSL repository.
4
What type of vulnerability is CVE-2026-6094?
CVE-2026-6094 is categorized as a heap buffer overread vulnerability.
5
What could potentially trigger CVE-2026-6094?
CVE-2026-6094 can be triggered by attacker-supplied data delivered via S/MIME or CMS.