PT-2026-99513 · Wpas+9 · Wpas+9
CVE-2026-93302
·
Published
2026-09-27
·
Updated
2026-09-29
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
wolfSSL (affected versions not specified)
Description
The
MatchTrustedPeer function ignores the public key used, which allows forged CA clones to pass verification. This issue occurs in builds where the WOLFSSL TRUST PEER CERT macro is enabled and CA certificates are loaded using the wolfSSL CTX trust peer cert() or wolfSSL trust peer cert() functions. If the OPENSSL COMPATIBLE DEFAULTS macro is also defined, the issue extends to all CA certificate loading. This configuration is common in autoconf builds used by software such as nginx, haproxy, stunnel, wpas, apache httpd, hitch, bind, rsyslog, and ffmpeg. A malicious (D)TLS server can bypass authentication if it knows which CAs the client accepts, and the issue similarly affects mutual authentication scenarios where the client knows the CAs loaded by the server.Recommendations
Update to the latest wolfSSL version.
Apply the fix patch.
Use the configure flag
--disable-openssl-compatible-defaults and avoid loading CAs with wolfSSL CTX trust peer cert() or wolfSSL trust peer cert().Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Bind
Ffmpeg
Haproxy
Hitch
Nginx
Rsyslog
Stunnel
Wolfssl
Wpas