https://seclists.org/oss-sec/2026/q2/1003: Common PKCS#7 / CMS parsing issues in OpenSSL, WolfSSL, Bouncy Castle, & GnuPG
Published Jun 23, 2026
·Updated
Affected Software
4 affected components
OpenSSL OpenSSL
wolfSSL wolfssl
Bouncy Castle Bouncy Castle
gnupg GnuPG
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXXX?
CVE-2026-XXXXX is considered a high severity vulnerability due to the potential for authentication tag length manipulation.
2
How do I fix CVE-2026-XXXXX?
To fix CVE-2026-XXXXX, update to the latest versions of OpenSSL, wolfSSL, Bouncy Castle, or GnuPG that include the security patches.
3
What systems are affected by CVE-2026-XXXXX?
CVE-2026-XXXXX affects various systems utilizing OpenSSL, wolfSSL, Bouncy Castle, and GnuPG for cryptographic functionality.
4
What types of attacks can be conducted using CVE-2026-XXXXX?
CVE-2026-XXXXX can enable attackers to perform brute force attacks through manipulated authentication tag lengths.
5
When was CVE-2026-XXXXX published?
CVE-2026-XXXXX was published on June 23, 2026.