CVE-2026-6094Disclosure(wolfssl / wolfssl)

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-25: 3Technical Details · 2026-06-25: 306-25
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6094 Heap Buffer Overread in PKCS7 EnvelopedData Parsing via S/MIME https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6094

    Post summary

    New CVE disclosed: heap buffer overread in S/MIME PKCS7 parsing; no PoC, exploit, patch, or active exploitation details provided.

    00000123
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered… https://www.cve.org/CVERecord?id=CVE-2026-6094 ----- Traducción: CVE-2026-6094 Lec… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-6094, detailing a heap buffer overread vulnerability in the wc_PKCS7_DecodeEnvelopedData function triggered by crafted PKCS7 payloads.

    0000044
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered… https://www.cve.org/CVERecord?id=CVE-2026-6094

    Post summary

    The post announces a heap buffer overread vulnerability in wc_PKCS7_DecodeEnvelopedData involving crafted PKCS7 data, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000989
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more