PT-2026-99515 · Wolfssl · Wolfssl
CVE-2026-94417
·
Published
2026-09-27
·
Updated
2026-09-29
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
wolfSSL versions prior to 5.9.3
Description
An issue exists when an application enables both Online Certificate Status Protocol (OCSP) and Certificate Revocation List (CRL) revocation checking on one
WOLFSSL CTX or certificate manager. In this configuration, the software skips the CRL check for any peer certificate that lacks an Authority Information Access OCSP URL, potentially accepting a certificate that the loaded CRL lists as revoked. This occurs because the soft-fail policy for a missing responder treats the absence of a responder as a success, making it indistinguishable from a positive response from the responder. The defect is located in the ProcessPeerCerts() function and is reachable over TLS 1.0 through TLS 1.3 and DTLS, affecting both clients verifying server certificates and servers verifying client certificates during mutual or post-handshake authentication. If the skipped check occurs on a chain certificate rather than the leaf, the unchecked intermediate is promoted into the certificate manager and remains a trusted signer for subsequent connections on that context.Recommendations
Update wolfSSL to a version newer than 5.9.2.
As a temporary mitigation, avoid calling both
wolfSSL CTX EnableOCSP() (or wolfSSL EnableOCSP() / wolfSSL CertManagerEnableOCSP()) and wolfSSL CTX EnableCRL() (or equivalents) simultaneously with a CRL loaded.
For long-running processes, the WOLFSSL CTX must be torn down after updating the library to ensure no compromised intermediate certificates remain trusted.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wolfssl