在存在非 dNSName 类型 SAN(例如 registeredID 或 iPAddress)但没有 dNSName 类型 SAN 的证书场景中,系统绕过了对主体通用名(Subject CN)中 dNSName 的名称约束检查。CN 作为 DNS 名称的后备机制原本仅在条件 成立时启用,而非基于“是否存在 dNSName SAN”的判断,从而导致域外范围的 CN 被错误接受。此漏洞源于 CVE-2026-6731 的不完整修复措施,该问题在 wolfSSL 5.9.2 版本中被引入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93302 | 8.3 HIGH | Trusted peer certificate match ignores public key, allowing forged CA clones |
| CVE-2026-89136 | 8.3 HIGH | Client accepts unsolicited RawPublicKey server certificate type |
| CVE-2026-89102 | 8.3 HIGH | OCSP stapling v2 multi accepts non-CA chain certificates as issuers |
| CVE-2026-93304 | 6.3 MEDIUM | (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange |
| CVE-2026-89133 | 6.3 MEDIUM | NameConstraints not enforced across unconstrained intermediate CA |
| CVE-2026-89135 | 6.3 MEDIUM | Failed X509_verify_cert leaves unverified CA in shared CertManager |
| CVE-2026-15442 | 2.3 LOW | Heap use-after-free on read during bidirectional (D)TLS shutdown |
| CVE-2026-94418 | 2.3 LOW | Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY |
| CVE-2026-94419 | 2.3 LOW | Client session cache reference poisoning allows resumption with wrong server |
| CVE-2026-94417 | 2.3 LOW | CRL check skipped when OCSP enabled and certificate has no OCSP URL |
No comments yet