OVERVIEW CVE-2026-5194 is a cryptographic validation flaw in ECDSA certificate verification that permits the acceptance of cryptographic digests smaller than specifications allow. The vulnerability stems from missing hash/digest size and Object Identifier (OID) validation checks in signature verification functions. This flaw is particularly concerning when EdDSA or ML-DSA algorithms are simultaneously enabled alongside ECDSA, potentially affecting multiple cryptographic implementations across various products and libraries. SEVERITY The vulnerability carries a CVSS score of 9.1 (CRITICAL) with an attack vector that is network-based, requires no privileges or user interaction, and causes complete compromise of confidentiality and integrity. The attack complexity is low, meaning exploitation requires minimal technical sophistication. The primary security impact is the degradation of ECDSA certificate-based authentication security, particularly when the public CA key is known to an attacker, enabling potential certificate forgery or authentication bypass attacks. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, and exploit code availability is unknown. The EPSS score of 0.0004 indicates this vulnerability is in the lower percentile of exploitation probability compared to other disclosed vulnerabilities, suggesting limited immediate threat despite its critical severity rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.12.0, < 5.9.1CPE match | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.