Out-of-bounds Read Affecting mtrojnar/osslsigncode package, versions [,2.13)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Out-of-bounds Read vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-MTROJNAROSSLSIGNCODE-16081989
  • published16 Apr 2026
  • disclosed9 Apr 2026
  • creditopera-aklajn

Introduced: 9 Apr 2026

CVE-2026-39856  (opens in a new tab)
CWE-125  (opens in a new tab)

How to fix?

Upgrade mtrojnar/osslsigncode to version 2.13 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Read via the pe_page_hash_calc function. An attacker can cause the process to crash by providing a crafted PE file with section headers that reference data beyond the end of the file, leading to an attempt to read from an invalid memory region. This can occur when signing a malicious PE file with page hashing enabled or when verifying a malicious signed PE file that already contains page hashes.

CVSS Base Scores

version 4.0
version 3.1