Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-89102— OCSP stapling v2 multi accepts non-CA chain certificates as issuers

Quick assessment

Affected
wolfSSL wolfSSL
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 wolfSSL 5.7.2 至 5.9.2 版本中,存在一个与 RFC 6961 相关、涉及 OCSP 响应多响应(multiple OCSP response)客户端实现的缺陷,可能导致证书伪造。当 wolfSSL 客户端启用了 OCSP 装订功能(通过 特性),并调用 时,客户端会将对端证书链中的任何证书都视为证书颁发机构(CA)证书,而未验证该证书是否确实具备颁发证书的权限。这意味着,攻击者只要拥有任何由客户端信任的 CA 所签发的证书(及其私钥),就可以伪造任意身份的有效证书,这些伪造证书将被客户端视为

CVSS 8.3 · High EPSS 0.25% · P15
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89102

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OCSP stapling v2 multi accepts non-CA chain certificates as issuers
Source: CVE Program / CVE List V5
Vulnerability Description
In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the HAVE_CERTIFICATE_STATUS_REQUEST_V2 feature and calls wolfSSL_UseOCSPStaplingV2(ssl, WOLFSSL_CSR2_OCSP_MULTI, options), the client accepts any certificate in the peer's chain as a certificate authority without verifying that the certificate is actually authorized to act as one. This means that an attacker who possesses any certificate that chains to a CA trusted by the client (along with its private key) can forge certificates for arbitrary identities that will be accepted as valid by the client. The end entity certificate of the server is stored in the persistent trust store, affecting subsequent connections that reuse the context even when OCSP multi usage is not employed. Found by internal wolfSSL testing.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL wolfSSL 5.7.2 ~ 5.9.2 -

II. Public POCs for CVE-2026-89102

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89102

请登录查看更多情报信息。

Other References for CVE-2026-89102 (1)

Same Patch Batch · wolfSSL · 2026-09-27 · 11 CVEs total

CVE-2026-93302 8.3 HIGH Trusted peer certificate match ignores public key, allowing forged CA clones
CVE-2026-89136 8.3 HIGH Client accepts unsolicited RawPublicKey server certificate type
CVE-2026-93304 6.3 MEDIUM (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
CVE-2026-89133 6.3 MEDIUM NameConstraints not enforced across unconstrained intermediate CA
CVE-2026-89134 6.3 MEDIUM Subject CN name-constraint check bypassed when non-DNS SAN present
CVE-2026-89135 6.3 MEDIUM Failed X509_verify_cert leaves unverified CA in shared CertManager
CVE-2026-15442 2.3 LOW Heap use-after-free on read during bidirectional (D)TLS shutdown
CVE-2026-94418 2.3 LOW Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
CVE-2026-94419 2.3 LOW Client session cache reference poisoning allows resumption with wrong server
CVE-2026-94417 2.3 LOW CRL check skipped when OCSP enabled and certificate has no OCSP URL

IV. Related Vulnerabilities

V. Comments for CVE-2026-89102

No comments yet


Leave a comment