PT-2026-52585 · Wolfssl+4 · Wolfssl+1

·

CVE-2026-6450

·

Published

2026-06-25

·

Updated

2026-07-14

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description A critical extension bypass exists in the ParseCRL Extensions() function. The issue occurs when critical extensions in a Certificate Revocation List (CRL)—a list of digital certificates that have been revoked by the issuing authority—are not properly enforced. This allows a crafted CRL containing an unhandled critical extension to be accepted, provided the CRL has a trusted signature and CRL support is enabled in the build.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6450
JLSEC-2026-751

Affected Products

Wolfssl
Wolfssl Jll