PT-2026-64471 · Julia · Wolfssl Jll
Published
2026-07-14
·
Updated
2026-07-14
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in
wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wolfssl Jll