PT-2026-99510 · Wolfssl · Wolfssl
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wolfSSL version 5.9.2
Description
A flaw exists where a certificate containing a Subject Alternative Name (SAN) other than a dNSName (such as
registeredID or iPAddress), but lacking a dNSName SAN, can bypass the Subject Common Name (CN) dNSName name-constraint check. This occurs because the fallback mechanism for treating the CN as a DNS name was incorrectly gated, allowing an out-of-scope CN to be accepted.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wolfssl