A newly disclosed vulnerability, CVE-2026-5194, affects wolfSSL and can cause ECDSA certificate verification routines to accept digests smaller than required because hash/digest size and OID checks are missing. The flaw is classified as CWE-295 and weakens certificate-based authentication by reducing the assurance that an ECDSA signature was validated against the proper digest constraints.
The issue impacts ECDSA/ECC verification in wolfSSL configurations where EdDSA or ML-DSA is also enabled, and the risk is greater when the public CA key is known. Public references point to a wolfSSL GitHub pull request as well as MITRE and NVD tracking, while severity data published by Tenable includes CVSS v2, v3, and v4 scoring that describes a network-reachable issue with significant confidentiality and integrity impact in newer versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security states that wolfSSL published a security advisory on June 23, 2026 addressing vulnerabilities in wolfSSL. The notice says versions prior to 5.9.2 are affected and recommends reviewing vendor guidance and upgrading to wolfSSL 5.9.2.
A new vulnerability, CVE-2026-5194, was recorded affecting wolfSSL. The flaw involves missing hash/digest size and OID checks that can let ECDSA certificate verification accept undersized digests in configurations where EdDSA or ML-DSA is also enabled, weakening certificate-based authentication when the public CA key is known.
wolfSSL released version 5.9.1 containing the fix for CVE-2026-5194, addressing improper acceptance of weak or undersized digests during signature validation. The release provided the vendor-shipped remediation after the earlier source-code fix was merged.
wolfSSL merged pull request #10131 into the master branch, adding stricter digest-size enforcement and OID agreement checks during signature generation and verification. The change was labeled for release 5.9.1 and aligns with the weakness later disclosed as CVE-2026-5194.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcehackread.com
Open sourcescworld.com
Open sourcecyber.gc.ca
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourcetenable.com
Open sourcegithub.com
Open sourcesecurity-tracker.debian.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.