PT-2026-99513 · Wpas+9 · Wpas+9

CVE-2026-93302

·

Published

2026-09-27

·

Updated

2026-09-29

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions wolfSSL (affected versions not specified)
Description The MatchTrustedPeer function ignores the public key used, which allows forged CA clones to pass verification. This issue occurs in builds where the WOLFSSL TRUST PEER CERT macro is enabled and CA certificates are loaded using the wolfSSL CTX trust peer cert() or wolfSSL trust peer cert() functions. If the OPENSSL COMPATIBLE DEFAULTS macro is also defined, the issue extends to all CA certificate loading. This configuration is common in autoconf builds used by software such as nginx, haproxy, stunnel, wpas, apache httpd, hitch, bind, rsyslog, and ffmpeg. A malicious (D)TLS server can bypass authentication if it knows which CAs the client accepts, and the issue similarly affects mutual authentication scenarios where the client knows the CAs loaded by the server.
Recommendations Update to the latest wolfSSL version. Apply the fix patch. Use the configure flag --disable-openssl-compatible-defaults and avoid loading CAs with wolfSSL CTX trust peer cert() or wolfSSL trust peer cert().

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93302

Affected Products

Apache Http Server
Bind
Ffmpeg
Haproxy
Hitch
Nginx
Rsyslog
Stunnel
Wolfssl
Wpas