Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5447

25
FAUCET Score

CVE-2026-5447 is a heap buffer overflow vulnerability in the CertFromX509 function that results from improper size handling of the AuthorityKeyIdentifier extension during X.509 certificate conversion. The specific products affected are not detailed in the provided data, but the vulnerability appears to impact certificate processing functionality across one or more applications. The vulnerability presents a moderate risk with a FAUCET Risk Score of 35.0/100. While specific CVSS metrics are unavailable, the heap buffer overflow nature of this defect could potentially allow memory corruption leading to denial of service or arbitrary code execution depending on exploitation conditions and the affected application's architecture. This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The extremely low EPSS score of 0.00043 indicates minimal current real-world exploitation activity and limited community attention, suggesting this remains a low-priority item for immediate remediation efforts compared to more widely exploited vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 5.9.1CPE match
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*
< 5.9.1CPE matchmatch criteria
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 1st percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-5447Moderate

Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier

Apr 14, 2026

References

github.com / wolfSSL/wolfssl/pull/10112
Issue TrackingPatch