
CVE-2026-5500 wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middl… https://www.cve.org/CVERecord?id=CVE-2026-5500
Post summary
The tweet announces a vulnerability in wolfSSL where the PKCS7 decoder does not sanitize AES‑GCM authentication tag length, detailing the flaw but not providing a patch, PoC, or evidence of exploitation.


