PT-2026-99515 · Wolfssl · Wolfssl

CVE-2026-94417

·

Published

2026-09-27

·

Updated

2026-09-29

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions wolfSSL versions prior to 5.9.3
Description An issue exists when an application enables both Online Certificate Status Protocol (OCSP) and Certificate Revocation List (CRL) revocation checking on one WOLFSSL CTX or certificate manager. In this configuration, the software skips the CRL check for any peer certificate that lacks an Authority Information Access OCSP URL, potentially accepting a certificate that the loaded CRL lists as revoked. This occurs because the soft-fail policy for a missing responder treats the absence of a responder as a success, making it indistinguishable from a positive response from the responder. The defect is located in the ProcessPeerCerts() function and is reachable over TLS 1.0 through TLS 1.3 and DTLS, affecting both clients verifying server certificates and servers verifying client certificates during mutual or post-handshake authentication. If the skipped check occurs on a chain certificate rather than the leaf, the unchecked intermediate is promoted into the certificate manager and remains a trusted signer for subsequent connections on that context.
Recommendations Update wolfSSL to a version newer than 5.9.2. As a temporary mitigation, avoid calling both wolfSSL CTX EnableOCSP() (or wolfSSL EnableOCSP() / wolfSSL CertManagerEnableOCSP()) and wolfSSL CTX EnableCRL() (or equivalents) simultaneously with a CRL loaded. For long-running processes, the WOLFSSL CTX must be torn down after updating the library to ensure no compromised intermediate certificates remain trusted.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94417

Affected Products

Wolfssl