Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.
An unauthenticated attacker can send crafted PKCS#7 messages with malformed Other Recipient Info that triggers an integer underflow, allowing the decryption process to read beyond intended memory boundaries and disclose sensitive data from memory.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
No patch information available
Monitor and validate PKCS#7 message structures before processing, particularly Other Recipient Info fields. Consider implementing input validation to detect and reject malformed recipient information. Apply patches or updates from the vendor once available. Restrict network access to systems processing PKCS#7 encrypted messages to trusted sources where possible.
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
NVD published the first details for CVE-2026-6678
Feedly found the first article mentioning CVE-2026-6678 . See article
A CVSS base score of 1 has been assigned.
GitHub Advisories released a security advisory .
CVE-2026-6678 | wolfSSL up to 5.9.1 integer underflow
CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
