CVE-2026-6678: Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info
Published Jun 25, 2026
·Updated
Integer underflow in wcPKCS7DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.
Affected Software
2 affected components
CyaSSL wc_PKCS7
wolfSSL wolfssl>=3.15.5<5.9.2
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-6678?
The severity of CVE-2026-6678 is rated as low with a CVSS score of 4.0.
2
How do I fix CVE-2026-6678?
You can fix CVE-2026-6678 by applying the available patch from the vendor.
3
What software is affected by CVE-2026-6678?
CVE-2026-6678 affects CyaSSL's wc_PKCS7 and wolfSSL's wolfssl.
4
What type of vulnerability is CVE-2026-6678?
CVE-2026-6678 is categorized as an Integer Underflow vulnerability.
5
What is the impact of CVE-2026-6678?
The impact of CVE-2026-6678 can lead to incorrect length handling during decryption.