Wolfssl · Wolfssl · CVE-2026-89134
**Name of the Vulnerable Software and Affected Versions**
wolfSSL version 5.9.2
**Description**
A flaw exists where a certificate containing a Subject Alternative Name (SAN) other than a dNSName (such as `registeredID` or `iPAddress`), but lacking a dNSName SAN, can bypass the Subject Common Name (CN) dNSName name-constraint check. This occurs because the fallback mechanism for treating the CN as a DNS name was incorrectly gated, allowing an out-of-scope CN to be accepted.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.