Executive brief
wolfSSL is a security library used to protect data and verify identities in embedded devices and cloud applications. A flaw in how the library verifies digital signatures (PKCS#7) could allow an attacker to trick the system into accepting a forged signature. This could lead to unauthorized access or the acceptance of malicious data as if it were from a trusted source.
Technical details
A signer confusion vulnerability exists in wolfSSL's PKCS7_verify function within the wolfcrypt/src/pkcs7.c component. The root cause is improper verification of cryptographic signatures (CWE-347), where the signer associated with a signature is not correctly bound to the signature itself. This flaw permits an attacker to present a forged signature that the library will incorrectly validate as authentic. The vulnerability affects versions 3.15.5 through 5.9.1 and was addressed in the 5.9.1 release via pull request #10203. Exploitation typically requires the attacker to be on the same adjacent network or provide a crafted PKCS#7 payload to an application using the library.
Affected products
- wolfSSL wolfSSL 3.15.5 through 5.9.1
Timeline
- 2026-04-13: other: Pull request with fixes submitted to GitHub
- 2026-04-24: patched: Fixes merged into master branch
- 2026-06-25: disclosed: CVE published to NVD