OVERVIEW CVE-2026-5504 is a padding oracle vulnerability in wolfSSL's PKCS7 CBC decryption implementation. The flaw exists because interior padding bytes are not properly validated during decryption operations, allowing attackers to recover plaintext data through repeated decryption queries with modified ciphertext. SEVERITY The vulnerability requires an attacker to have direct access to perform repeated decryption queries against the affected system, indicating an attack complexity that is not trivial. While specific CVSS metrics are not available, the EPSS score of 0.00025 indicates this vulnerability has exceptionally low predicted exploitation probability. The potential impact is confidentiality breach through plaintext recovery, though the practical risk appears limited by access requirements and exploitation difficulty. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog. The FAUCET Risk Score of 35.0 out of 100 further suggests low current threat activity. The vulnerability remains inactive on security hotlists, and no public exploit code availability has been reported, indicating minimal community attention to date.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 5.9.0CPE match | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* | ||
<= 5.9.0CPE matchmatch criteria | cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.