Logo
vulnerabilityCVE-2026-5466
Name
CVE-2026-5466
Source
NVD ( link)Debian ( link)
Description
wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_read_unsigned_bin` with no check that they lie in `[1, q-1]`. A crafted forged signature could verify against any message for any identity, using only publicly-known constants.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
wolfssl
Not Affected

Vulnerability Ratings#


7.6
CVSSv4
8.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
5.9.1
Not Affected
buildroot
master
5.9.1
Not Affected
openwrt
master
5.9.1-r1
Not Affected
openwrt
openwrt-25.12
5.9.1-r1
Not Affected
yocto
kirkstone
5.2.0
Exploitable
yocto
scarthgap
5.7.2
Exploitable