QSearchQSearch

CVE-2026-5194

9.1 CRITICAL

Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropri...

Published: 2026-04-09 · Last updated: 2026-04-16

Severity and scoring

CVSS
9.1 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE
CWE-295

Affected products

VendorProduct
wolfsslwolfssl

Description

Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature verification functions. This could lead to reduced security of ECDSA certificate-based authentication if the public CA key used is also known. This affects ECDSA/ECC verification when EdDSA or ML-DSA is also enabled.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-45170 Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validati...
  • CVE-2026-45175 Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes
  • CVE-2026-40992 Spring Boot's Mail auto-configuration does not enable hostname verification (5.0 MEDIUM)
  • CVE-2026-53475 A flaw was found in assisted-migration-agent (9.3 CRITICAL)
  • CVE-2026-9758 Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered tru... (7.3 HIGH)