A critical vulnerability identified as CVE 2026 5194 has been discovered in the wolfSSL SSL TLS library affecting how certificate signatures are verified. The flaw allows improper validation of hash algorithms and digest sizes during signature checks such as ECDSA. This means an attacker could create forged certificates that may be accepted as valid by vulnerable systems. As a result devices or applications could unknowingly trust malicious servers leading to risks such as unauthorized access or interception of sensitive data. The issue occurs because wolfSSL does not properly enforce checks on digest size and algorithm identifiers during signature verification. In some cases it may accept smaller or weaker digests than required for the specific key type which weakens the overall cryptographic strength. Since certificate validation is a core part of secure communication this flaw reduces trust in authentication mechanisms. The vulnerability impacts several algorithms including ECDSA ECC DSA ML DSA Ed25519 and Ed448 especially when multiple signature options are enabled. wolfSSL is widely used across embedded systems IoT devices and industrial environments which increases the potential impact of this issue. Attackers could exploit this weakness to impersonate trusted entities under certain conditions. The vulnerability has been fixed in wolfSSL version 5.9.1 and organizations are strongly advised to upgrade immediately review affected systems and follow vendor guidance where customized or bundled versions are in use
Two high-severity security vulnerabilities have been identified in Composer, posing a risk of arbitrary command execution if exploited. These flaws affect the Perforce VCS (version...
Rockstar Games has confirmed a data breach after the ShinyHunters extortion group leaked stolen data on its leak site. The attackers claim the data was obtained using compromised a...
Microsoft has released its April 2026 Patch Tuesday security updates, addressing 167 vulnerabilities, including two zero-day flaws. Among the 167 vulnerabilities, 8 are classified ...