Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-5295— Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID

EPSS 0.02% · P4
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-5295

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stack Buffer Overflow in wolfSSL PKCS7 wc_PKCS7_DecryptOri() via Oversized OID
Source: NVD (National Vulnerability Database)
Vulnerability Description
A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc_PKCS7_DecryptOri() function in wolfcrypt/src/pkcs7.c. When processing a CMS EnvelopedData message containing an OtherRecipientInfo (ORI) recipient, the function copies an ASN.1-parsed OID into a fixed 32-byte stack buffer (oriOID[MAX_OID_SZ]) via XMEMCPY without first validating that the parsed OID length does not exceed MAX_OID_SZ. A crafted CMS EnvelopedData message with an ORI recipient containing an OID longer than 32 bytes triggers a stack buffer overflow. Exploitation requires the library to be built with --enable-pkcs7 (disabled by default) and the application to have registered an ORI decrypt callback via wc_PKCS7_SetOriDecryptCb().
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
栈缓冲区溢出
Source: NVD (National Vulnerability Database)
Vulnerability Title
wolfSSL 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
wolfSSL(CyaSSL)是美国wolfSSL公司的一个针对嵌入式系统开发人员使用的小的、可移植的嵌入式SSL编程库。 wolfSSL存在安全漏洞,该漏洞源于wc_PKCS7_DecryptOri函数中的PKCS7实现存在栈缓冲区溢出,可能导致处理包含OtherRecipientInfo接收者的CMS EnvelopedData消息时触发栈缓冲区溢出。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
wolfSSLwolfSSL 0 ~ 5.9.1 -

II. Public POCs for CVE-2026-5295

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-5295

登录查看更多情报信息。

Same Patch Batch · wolfSSL · 2026-04-09 · 16 CVEs total

CVE-2026-5263URI nameConstraints not enforced in ConfirmNameConstraints()
CVE-2026-5187Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL
CVE-2026-5264DTLS 1.3 ACK heap buffer overflow
CVE-2026-5393OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS
CVE-2026-5446wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse
CVE-2026-5504PKCS7 CBC Padding Oracle — Plaintext Recovery
CVE-2026-5447Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier
CVE-2026-5778Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path.
CVE-2026-5772MatchDomainName 1-Byte Stack Buffer Over-Read in Hostname Validation
CVE-2026-5507Session Cache Restore — Arbitrary Free via Deserialized Pointer
CVE-2026-5194wolfSSL ECDSA Certificate Verification
CVE-2026-5392wolfSSL heap OOB read in PKCS7 SignedData streaming
CVE-2026-5460Heap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3
CVE-2026-5503out-of-bounds write in TLSX_EchChangeSNI via attacker-controlled publicName
CVE-2026-54481-2 Byte Buffer Overflow in wolfSSL_X509_notAfter/notBefore

IV. Related Vulnerabilities

V. Comments for CVE-2026-5295

No comments yet


Leave a comment