OVERVIEW CVE-2026-39855 is an integer underflow vulnerability in osslsigncode version 2.12 and earlier, a cryptographic tool used for Authenticode signing and timestamping of PE executable files. The vulnerability exists in the PE page-hash computation function (pe_page_hash_calc()), where insufficient input validation allows malicious PE files to trigger an out-of-bounds heap read by crafting a SizeOfHeaders value larger than SectionAlignment. The flaw affects both signing operations with page hashing enabled and verification of previously signed files. SEVERITY The vulnerability has a CVSS v3.1 score of 5.5 (Medium) with a local attack vector requiring user interaction but no special privileges. Attack complexity is low, and the primary impact is availability denial through process crashes resulting from the out-of-bounds read. No confidentiality or integrity impact is present. The EPSS score of 0.00019 suggests currently minimal exploitation likelihood relative to other disclosed vulnerabilities. EXPLOITATION STATUS The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows no indicators of active exploitation in the wild. No public exploit code or proof-of-concept has achieved significant community attention based on available telemetry. The vulnerability remains classified as inactive on threat tracking lists, indicating limited real-world threat activity at this time. Organizations using osslsigncode should prioritize upgrading to version 2.13 where the fix has been implemented.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.13CPE matchmatch criteria | cpe:2.3:a:osslsigncode_project:osslsigncode:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.