PT-2026-99517 · Wolfssl · Wolfssl

CVE-2026-94419

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions wolfSSL versions 5.3.0 through 5.9.2
Description When NO SESSION CACHE REF is undefined, the wolfSSL get session() function returns a ClientSession reference to the process-global SessionCache instead of a session object. The ClientSessionToSession() function validates this reference using only a hash of the session ID. Since TLS 1.2 session IDs are server-chosen and transmitted in cleartext, the AddSessionToCache() function can match a session from a different server with the same ID, overwriting the client-side entry with the attacker's master secret, cipher suite, and version. This allows an attacker to be accepted as the original server during an abbreviated handshake for TLS 1.2 and below or DTLS 1.2 and below, as no Certificate message is sent, bypassing chain verification and the wolfSSL check domain name() function. This issue affects builds using a plain ./configure, --enable-opensslextra, or --enable-opensslall, and requires the application to use the legacy reference flow involving wolfSSL get session() or SSL get session() followed by wolfSSL set session(). The poisoned entry persists in the global cache across WOLFSSL CTX boundaries until eviction or timeout.
Recommendations Update wolfSSL to a version newer than 5.9.2. As a temporary mitigation, avoid using the wolfSSL get session() or SSL get session() functions followed by wolfSSL set session(), and instead use wolfSSL get1 session() which returns the session object directly.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94419

Affected Products

Wolfssl