在 wolfSSL 5.7.2 至 5.9.2 版本中,存在一个与 RFC 6961 相关、涉及 OCSP 响应多响应(multiple OCSP response)客户端实现的缺陷,可能导致证书伪造。当 wolfSSL 客户端启用了 OCSP 装订功能(通过 特性),并调用 时,客户端会将对端证书链中的任何证书都视为证书颁发机构(CA)证书,而未验证该证书是否确实具备颁发证书的权限。这意味着,攻击者只要拥有任何由客户端信任的 CA 所签发的证书(及其私钥),就可以伪造任意身份的有效证书,这些伪造证书将被客户端视为
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93302 | 8.3 HIGH | Trusted peer certificate match ignores public key, allowing forged CA clones |
| CVE-2026-89136 | 8.3 HIGH | Client accepts unsolicited RawPublicKey server certificate type |
| CVE-2026-93304 | 6.3 MEDIUM | (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange |
| CVE-2026-89133 | 6.3 MEDIUM | NameConstraints not enforced across unconstrained intermediate CA |
| CVE-2026-89134 | 6.3 MEDIUM | Subject CN name-constraint check bypassed when non-DNS SAN present |
| CVE-2026-89135 | 6.3 MEDIUM | Failed X509_verify_cert leaves unverified CA in shared CertManager |
| CVE-2026-15442 | 2.3 LOW | Heap use-after-free on read during bidirectional (D)TLS shutdown |
| CVE-2026-94418 | 2.3 LOW | Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY |
| CVE-2026-94419 | 2.3 LOW | Client session cache reference poisoning allows resumption with wrong server |
| CVE-2026-94417 | 2.3 LOW | CRL check skipped when OCSP enabled and certificate has no OCSP URL |
No comments yet