OVERVIEW CVE-2026-39856 is an out-of-bounds read vulnerability in osslsigncode versions 2.12 and earlier, a tool used for Authenticode signing and timestamping of PE (Portable Executable) files. The flaw exists in the PE page-hash computation function, which fails to validate that section header pointers reference valid file regions. An attacker can craft a malicious PE file with section headers pointing beyond the file's boundaries to trigger an out-of-bounds read during page hash processing. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.5 (Medium) with a local attack vector, low complexity, and no privileges required. The primary impact is availability, as the out-of-bounds read can crash the osslsigncode process. While confidentiality and integrity are not directly compromised, exploitation occurs through user interaction (receipt of a malicious PE file) and is triggered automatically during signing operations with page hashing enabled or during verification of pre-signed malicious files. EXPLOITATION STATUS There is no evidence of active exploitation. The CVE is not listed on CISA's Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00019 indicates minimal real-world exploitation probability. Community attention appears limited. The vulnerability is readily fixable through upgrading to osslsigncode version 2.13 or later, which implements proper validation of section header boundaries.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.13CPE matchmatch criteria | cpe:2.3:a:osslsigncode_project:osslsigncode:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.