Skip to main content
Loading…
    CVE-2026-5466 — wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_read_unsigned_bin` with no check that they lie in `[1, q-1]`. A crafted forg — CVE Database · The Intelligence Room