PT-2026-52599 · Wolfssl · Wolfssl

CVE-2026-55962

·

Published

2026-06-25

·

Updated

2026-07-14

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions wolfSSL (affected versions not specified)
Description A TLS 1.3 post-handshake authentication (PHA) issue exists where a server may accept a client's Finished message even if the client has not provided a Certificate and CertificateVerify. This occurs because an exemption allowing empty or absent peer certificates, intended only for the initial handshake, was incorrectly applied while a post-handshake CertificateRequest was outstanding. This affects TLS 1.3 servers built with post-handshake authentication support (WOLFSSL POST HANDSHAKE AUTH or --enable-postauth), which enable WOLFSSL VERIFY POST HANDSHAKE and utilize the wolfSSL request certificate() function to request a client certificate after the handshake. Clients and servers not using post-handshake authentication are not affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55962
JLSEC-2026-737

Affected Products

Wolfssl