
PKCS#7 AES-GCM tag truncation enables auth bypass in wolfSSL
CVE-2026-5500 discloses a High-severity AES-GCM tag-length validation flaw in `wolfSSL <= 5.9.0` PKCS#7 decoding, enabling man-in-the-middle authentication bypass via tag truncation.
NewsCryptographyLibrary Security
2 minToday
