CVE-2026-5466Disclosure(wolfssl / wolfssl)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_read_unsigned_bin` with no check that they lie in `[1, q-1]`. A crafted forged signature could verify against any message for any identity, using only publicly-known constants.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-10); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-10: 2Mentions · 2026-04-11: 1Technical Details · 2026-04-10: 204-1004-11
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-102
Disclosure2
2026-04-111
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5466 📊 Severity: 7.6 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5466 #CVE-2026-5466 #CVE #High #CyberSecurity #InfoSec https://t.co/iZO5fxNIje

    Post summary

    The tweet simply announces the CVE-2026-5466 with basic severity information, offering no further technical details, exploitation evidence, or mitigation guidance.

    0000042
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5466 wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_read_unsigned_bin` with no check that they lie i… https://www.cve.org/CVERecord?id=CVE-2026-5466

    Post summary

    The text announces CVE-2026-5466, noting a flaw in wolfSSL's ECCSI verifier where scalar values are not validated, without mentioning any PoC, exploit, patch, or active exploitation.

    00000107
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5466 Signature Forgery in wolfSSL ECCSI Verifier via Unchecked Scalar Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5466

    Post summary

    The text announces CVE‑2026‑5466, explaining it as a signature forgery issue in wolfSSL ECCSI due to unchecked scalar validation, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more