JLSEC-2026-754

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-754.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-754.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-754
Upstream
  • EUVD-2026-39556
  • GHSA-6q89-vxvr-wgv2
Published
2026-07-14T21:41:35.775Z
Modified
2026-07-25T18:24:01.495224390Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
  • 1.0 (Low) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear CVSS Calculator
Summary
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded...
Details

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6681",
            "database_specific": {
                "status": "Analyzed"
            },
            "modified": "2026-06-27T20:02:40.840Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-6681",
            "imported": "2026-07-17T22:36:46.697Z",
            "id": "CVE-2026-6681",
            "published": "2026-06-25T21:16:28.283Z"
        },
        {
            "html_url": "https://github.com/advisories/GHSA-6q89-vxvr-wgv2",
            "imported": "2026-07-17T22:36:46.845Z",
            "modified": "2026-06-27T21:30:27Z",
            "url": "https://api.github.com/advisories/GHSA-6q89-vxvr-wgv2",
            "id": "GHSA-6q89-vxvr-wgv2",
            "published": "2026-06-25T21:31:32Z"
        },
        {
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39556",
            "imported": "2026-07-17T22:36:56.723Z",
            "modified": "2026-06-26T13:14:09Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-39556",
            "id": "EUVD-2026-39556",
            "published": "2026-06-25T20:11:39Z"
        }
    ]
}
References

Affected packages

Julia / wolfSSL_jll

Package

Name
wolfSSL_jll
Purl
pkg:julia/wolfSSL_jll?uuid=98c43586-9870-5ae5-ab22-acc77b9bbdb5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.9.2+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-754.json"