CVE-2026-4159 | wolfSSL up to 5.8.x CMS EnvelopedData Message wc_PKCS7_DecodeEnvelopedData out-of-bounds
A vulnerability classified as problematic was found in wolfSSL up to 5.8.x. This affects the function wc_PKCS7_DecodeEnvelopedData of the component CMS EnvelopedData Message Handler. The manipulation results in out-of-bounds read.
This vulnerability is identified as CVE-2026-4159. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is advised.