wolfSSL 5.9.2 及更早版本中存在一个 X.509 证书验证逻辑缺陷。当在带有名称约束(NameConstraints)的中间证书 CA 与叶子证书之间存在一个无约束的 CA 层级时,该漏洞导致 wolfSSL 无法正确强制执行 NameConstraints 扩展。由于链遍历(chain-walking)状态机中存在一个错误——在遇到没有 NameConstraints 的中间证书时会重置验证状态,从而使 wolfSSL 错误地接受了本不应被允许覆盖的主机名对应的证书,进而绕过了密码学委托控制。此缺陷存
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93302 | 8.3 HIGH | Trusted peer certificate match ignores public key, allowing forged CA clones |
| CVE-2026-89136 | 8.3 HIGH | Client accepts unsolicited RawPublicKey server certificate type |
| CVE-2026-89102 | 8.3 HIGH | OCSP stapling v2 multi accepts non-CA chain certificates as issuers |
| CVE-2026-93304 | 6.3 MEDIUM | (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange |
| CVE-2026-89134 | 6.3 MEDIUM | Subject CN name-constraint check bypassed when non-DNS SAN present |
| CVE-2026-89135 | 6.3 MEDIUM | Failed X509_verify_cert leaves unverified CA in shared CertManager |
| CVE-2026-15442 | 2.3 LOW | Heap use-after-free on read during bidirectional (D)TLS shutdown |
| CVE-2026-94418 | 2.3 LOW | Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY |
| CVE-2026-94419 | 2.3 LOW | Client session cache reference poisoning allows resumption with wrong server |
| CVE-2026-94417 | 2.3 LOW | CRL check skipped when OCSP enabled and certificate has no OCSP URL |
No comments yet