PT-2026-99529 · Wolfssl · Wolfssl
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
wolfSSL versions prior to 5.9.3
Description
A flaw exists in the X.509 certificate validation logic regarding the enforcement of NameConstraints extensions. When an unconstrained CA tier exists between a name-constrained intermediate CA and the leaf certificate, a chain-walking state-machine bug resets the validation state. This allows the software to incorrectly accept certificates for hostnames they are not authorized to cover, bypassing cryptographic delegation controls. This issue occurs in the default build configuration when using certificates with name constraint extensions.
Recommendations
Update wolfSSL to version 5.9.3 or later.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wolfssl