Overview
What is CVE-2026-6094?
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.
Vulnerability intelligence
CVE-2026-6094 and is rated Critical severity with a CVSS score of 9.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.