Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5194

36
FAUCET Score

OVERVIEW CVE-2026-5194 is a cryptographic validation flaw in ECDSA certificate verification that permits the acceptance of cryptographic digests smaller than specifications allow. The vulnerability stems from missing hash/digest size and Object Identifier (OID) validation checks in signature verification functions. This flaw is particularly concerning when EdDSA or ML-DSA algorithms are simultaneously enabled alongside ECDSA, potentially affecting multiple cryptographic implementations across various products and libraries. SEVERITY The vulnerability carries a CVSS score of 9.1 (CRITICAL) with an attack vector that is network-based, requires no privileges or user interaction, and causes complete compromise of confidentiality and integrity. The attack complexity is low, meaning exploitation requires minimal technical sophistication. The primary security impact is the degradation of ECDSA certificate-based authentication security, particularly when the public CA key is known to an attacker, enabling potential certificate forgery or authentication bypass attacks. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, and exploit code availability is unknown. The EPSS score of 0.0004 indicates this vulnerability is in the lower percentile of exploitation probability compared to other disclosed vulnerabilities, suggesting limited immediate threat despite its critical severity rating.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.12.0, < 5.9.1CPE match
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
HIGH
SS Integrity
LOW
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
36.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0045 is in the 14th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-5194Critical

wolfSSL ECDSA Certificate Verification

Apr 14, 2026

References

anthropic.com / research/glasswing-initial-update
github.com / wolfSSL/wolfssl/pull/10131
Issue Tracking