Junglewise Threat Intelligence

CVE-2026-55961: wolfSSL signature bypass in PKCS7_verify compatibility API

CVE-2026-55961 · Severity: info · CVSS 8.2 · Published 2026-06-25

Technologies: Wolfssl. Vendors: Wolfssl.

Executive brief

A vulnerability in the wolfSSL encryption library could allow unauthenticated data to be incorrectly treated as verified. This occurs when the library processes specific 'degenerate' security certificates that contain no actual signature, yet the system reports a successful verification. This could allow an attacker to bypass security checks in applications that rely on wolfSSL's OpenSSL compatibility features to validate signed data.

Technical details

A vulnerability exists in the wolfSSL_PKCS7_verify() function within the OpenSSL compatibility layer. When processing a 'degenerate' PKCS#7 object (one containing only certificates but no signers), the signerInfos field is empty. The underlying verification logic incorrectly treats the absence of a signature as a successful verification of the signed data. This allows an attacker to provide unauthenticated content that the application will treat as valid. The issue persists even if the PKCS7_NOVERIFY flag is set, as that flag is only intended to skip certificate chain validation, not the existence of a signature itself. The vulnerability is fixed in version 5.9.1.

Affected products

  • wolfSSL wolfSSL 3.15.7 through 5.9.0

Timeline

  • 2026-06-17: patched: Fix merged into master branch via PR 10702
  • 2026-06-25: disclosed: CVE published and advisory released

References

Related threats