Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39855

21
FAUCET Score

OVERVIEW CVE-2026-39855 is an integer underflow vulnerability in osslsigncode version 2.12 and earlier, a cryptographic tool used for Authenticode signing and timestamping of PE executable files. The vulnerability exists in the PE page-hash computation function (pe_page_hash_calc()), where insufficient input validation allows malicious PE files to trigger an out-of-bounds heap read by crafting a SizeOfHeaders value larger than SectionAlignment. The flaw affects both signing operations with page hashing enabled and verification of previously signed files. SEVERITY The vulnerability has a CVSS v3.1 score of 5.5 (Medium) with a local attack vector requiring user interaction but no special privileges. Attack complexity is low, and the primary impact is availability denial through process crashes resulting from the out-of-bounds read. No confidentiality or integrity impact is present. The EPSS score of 0.00019 suggests currently minimal exploitation likelihood relative to other disclosed vulnerabilities. EXPLOITATION STATUS The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows no indicators of active exploitation in the wild. No public exploit code or proof-of-concept has achieved significant community attention based on available telemetry. The vulnerability remains classified as inactive on threat tracking lists, indicating limited real-world threat activity at this time. Organizations using osslsigncode should prioritize upgrading to version 2.13 where the fix has been implemented.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.13CPE matchmatch criteria
cpe:2.3:a:osslsigncode_project:osslsigncode:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
4.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 5th percentile among its peer group of 5,765 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-39855Moderate

osslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read

Apr 2, 2026

References

github.com / mtrojnar/osslsigncode/commit/2a5409b7c4b6c6fad2b093531e8fea6cf08e1568
Patch
github.com / mtrojnar/osslsigncode/releases/tag/2.13
ProductRelease Notes
github.com / mtrojnar/osslsigncode/security/advisories/GHSA-76vv-x5rr-q3mr
PatchVendor Advisory