CVE-2026-5393 PUBLISHED

OOB Read in DoTls13CertificateVerify with WOLFSSL_DUAL_ALG_CERTS

Assigner: wolfSSL
Reserved: 01.04.2026 Published: 09.04.2026 Updated: 10.04.2026

Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on crafted input. This can only occur when --enable-experimental and --enable-dual-alg-certs is used when building wolfSSL.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor wolfSSL
Product wolfSSL
Versions Default: unaffected
  • affected from 0 to 5.9.1 (excl.)

Credits

  • Sunwoo Lee, (Korea Institute of Energy Technology, KENTECH) for testing other
  • Woohyun Choi, (Korea Institute of Energy Technology, KENTECH) for testing other
  • Seunghyun Yoon, (Korea Institute of Energy Technology, KENTECH) for testing other

References

Problem Types

  • CWE-125 Out-of-bounds Read CWE