PT-2026-52526 · Wolfssl · Wolfssl

CVE-2026-55961

·

Published

2026-06-25

·

Updated

2026-07-14

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions wolfSSL (affected versions not specified)
Description In OpenSSL compatibility builds, the wolfSSL PKCS7 verify() function incorrectly returns a success status when processing a degenerate PKCS#7 object that contains only certificates and no signer. Because such objects have empty signerInfos, the signed-data verification process succeeds without actually authenticating any content. This issue persists even when the PKCS7 NOVERIFY flag is used, as that flag is intended to suppress certificate chain validation rather than waive the requirement for a signature to exist. This affects systems calling the PKCS7 verify() compatibility API on potentially degenerate PKCS#7 bundles.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55961
JLSEC-2026-736

Affected Products

Wolfssl