Junglewise Threat Intelligence

CVE-2026-5393: wolfSSL out-of-bounds read in dual-algorithm CertificateVerify processing

CVE-2026-5393 · Severity: critical · CVSS 9.1 · Published 2026-04-10

Technologies: Wolfssl. Vendors: Wolfssl.

Executive brief

wolfSSL is a lightweight security library used to provide encrypted communications for applications and embedded devices. A vulnerability in how the library handles specific types of digital certificates could allow an attacker to crash a service or potentially access sensitive information from the system's memory. This issue only affects systems where specific experimental features were manually enabled during the software's build process.

Technical details

An out-of-bounds read vulnerability exists in wolfSSL's handling of dual-algorithm CertificateVerify messages. The flaw is triggered during the parsing of crafted input when the library is compiled with experimental dual-algorithm certificate support (--enable-experimental and --enable-dual-alg-certs). An unauthenticated remote attacker can exploit this by sending a specially crafted handshake message, leading to a crash (DoS) or the leakage of sensitive memory contents. The issue was addressed in version 5.9.1 by adding proper bounds checking when parsing dual-algorithm certificate signatures.

Affected products

  • wolfSSL wolfSSL versions up to (excluding) 5.9.1

Timeline

  • 2026-03-26: other: Fix submitted via pull request
  • 2026-03-30: patched: Fix merged into master branch
  • 2026-04-09: disclosed: Initial CVE disclosure by wolfSSL
  • 2026-04-10: advisory: NVD publication date

References

Related threats