PT-2026-52526 · Wolfssl · Wolfssl
CVE-2026-55961
·
Published
2026-06-25
·
Updated
2026-07-14
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
wolfSSL (affected versions not specified)
Description
In OpenSSL compatibility builds, the
wolfSSL PKCS7 verify() function incorrectly returns a success status when processing a degenerate PKCS#7 object that contains only certificates and no signer. Because such objects have empty signerInfos, the signed-data verification process succeeds without actually authenticating any content. This issue persists even when the PKCS7 NOVERIFY flag is used, as that flag is intended to suppress certificate chain validation rather than waive the requirement for a signature to exist. This affects systems calling the PKCS7 verify() compatibility API on potentially degenerate PKCS#7 bundles.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wolfssl