CVE-2026-6094: Heap Buffer Overread Vulnerability in PKCS7 Processing

CVE-2026-6094: Heap Buffer Overread Vulnerability in PKCS7 Processing

First seen 26 Jun 2026, 11:07 UTC Feedlycve.akaoma.comnvd.nist.govcve.reportosv.dev+1 88% similarity 54.3
Share:

Article Content

Browse articles
ThreatCluster

CVE-2026-6094 is a heap buffer overread vulnerability found in the wc_PKCS7_DecodeEnvelopedData function, which processes crafted PKCS7 EnvelopedData structures. This vulnerability can be exploited by unauthenticated attackers through specially crafted S/MIME or CMS messages, potentially disclosing sensitive data from adjacent memory regions. Currently, there is no public proof-of-concept or evidence of active exploitation. The CVSS base score assigned to this vulnerability is 6.3, indicating a medium severity level. Security teams are advised to monitor for updates from wolfSSL and restrict processing of untrusted S/MIME and CMS messages until a patch is available. Input validation on PKCS7 EnvelopedData structures is also recommended as a precautionary measure. The vulnerability affects systems using wolfSSL versions up to 5.9.1-0.1 on Debian.

Key Points: • CVE-2026-6094 allows unauthenticated attackers to exploit heap buffer overreads. • Vulnerability can be triggered via crafted S/MIME or CMS messages. • No patch is currently available; monitoring and input validation are recommended.

ThreatCluster AI

Timeline

2026-06-25
CVE-2026-6094 published
CVE-2026-6094 was officially published, detailing the heap buffer overread vulnerability.
Feedly
2026-06-26
Vulnerability details reported
Multiple sources reported on CVE-2026-6094, highlighting its exploitability and impact.
cve.akaoma.com
2026-06-26
NVD entry created
The National Vulnerability Database added CVE-2026-6094 to its records, indicating ongoing enrichment.
nvd.nist.gov
2026-06-26
CVE-2026-6094 severity assessed
The CVSS base score of 6.3 was confirmed, categorizing the vulnerability as medium severity.
cve.report

Community

Browse all →