CVE-2026-6681: PKCS#7 decode ignores caller output buffer size, writing past buffer bounds
Published Jun 25, 2026
·Updated
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.
Affected Software
2 affected components
wolfSSL wolfssl<=5.9.0
wolfSSL wolfssl>=3.10.0<5.9.1
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-6681?
The severity of CVE-2026-6681 is low, with a CVSS score of 4.0.
2
What does CVE-2026-6681 affect?
CVE-2026-6681 affects wolfSSL versions 5.9.0 and earlier.
3
How do I fix CVE-2026-6681?
To fix CVE-2026-6681, update to wolfSSL version 5.9.1 or later.
4
What is the nature of the vulnerability in CVE-2026-6681?
CVE-2026-6681 is caused by the PKCS#7 decode path ignoring the caller-supplied output buffer size, allowing potential buffer overflows.
5
When was CVE-2026-6681 published?
CVE-2026-6681 was published on June 25, 2026.