PT-2026-99529 · Wolfssl · Wolfssl

·

CVE-2026-89133

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions wolfSSL versions prior to 5.9.3
Description A flaw exists in the X.509 certificate validation logic regarding the enforcement of NameConstraints extensions. When an unconstrained CA tier exists between a name-constrained intermediate CA and the leaf certificate, a chain-walking state-machine bug resets the validation state. This allows the software to incorrectly accept certificates for hostnames they are not authorized to cover, bypassing cryptographic delegation controls. This issue occurs in the default build configuration when using certificates with name constraint extensions.
Recommendations Update wolfSSL to version 5.9.3 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89133

Affected Products

Wolfssl