CVE-2026-5447 is a heap buffer overflow vulnerability in the CertFromX509 function that results from improper size handling of the AuthorityKeyIdentifier extension during X.509 certificate conversion. The specific products affected are not detailed in the provided data, but the vulnerability appears to impact certificate processing functionality across one or more applications. The vulnerability presents a moderate risk with a FAUCET Risk Score of 35.0/100. While specific CVSS metrics are unavailable, the heap buffer overflow nature of this defect could potentially allow memory corruption leading to denial of service or arbitrary code execution depending on exploitation conditions and the affected application's architecture. This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The extremely low EPSS score of 0.00043 indicates minimal current real-world exploitation activity and limited community attention, suggesting this remains a low-priority item for immediate remediation efforts compared to more widely exploited vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 5.9.1CPE match | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* | ||
< 5.9.1CPE matchmatch criteria | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.