目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-93302— 可信对等证书匹配忽略公钥,允许伪造CA克隆

一分钟漏洞结论

影响对象
wolfSSL wolfSSL
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

函数忽略了所使用的公钥,导致伪造的 CA 克隆可以通过验证。受影响的版本是任何启用 宏,并通过 或 函数加载 CA 证书的版本。攻击者必须知晓哪些证书被加载到上述两个 API 中,才能利用此漏洞。 如果同时定义了 宏,则受影响的功能范围会扩大,涵盖所有 CA 证书的加载操作。在使用自动配置(autoconf)构建时(例如 nginx、haproxy、stunnel、wpas、apache httpd、hitch、bind、rsyslog、ffmpeg、all、distro 等),这两个宏通常都会被定义。 当证书被标

CVSS 8.3 · High EPSS 0.36% · P28

可能的 ATT&CK 技术 1 AI

T1557 · Adversary-in-the-Middle
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-93302 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Trusted peer certificate match ignores public key, allowing forged CA clones
来源: CVE Program / CVE List V5
Vulnerability Description
MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). The peer must know the certificates being loaded to either of those APIs to take advantage of the issue. When OPENSSL_COMPATIBLE_DEFAULTS is also defined this widens the affected API to include all CA certificate loading. Both macros are defined when using autoconf builds such as (nginx, haproxy, stunnel, wpas, apache httpd, hitch, bind, rsyslog, ffmpeg, all, distro). When the certificate is listed as a trusted peer certificate the issue previously allowed for a malicious (D)TLS server to bypass authentication once knowing which CA’s the client would accept. This also affects mutual authentication cases where the client knows which CA’s the server has loaded. If building with any of these configurations and using (D)TLS where the loaded CA’s could be known and authentication of the peer is desired, users should either: update to the latest wolfSSL version, apply the fix patch, or use the configure flag --disable-openssl-compatible-defaults and not load CA’s with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert() to mitigate the issue.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
wolfSSL wolfSSL 5.3.0 ~ 5.9.2 -

二、漏洞 CVE-2026-93302 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-93302 的情报信息

请登录查看更多情报信息。

CVE-2026-93302 其他参考 (1)

同批安全公告 · wolfSSL · 2026-09-27 · 共 11 条

CVE-2026-89136 8.3 HIGH 客户端接受未请求的RawPublicKey服务器证书类型
CVE-2026-89102 8.3 HIGH OCSP stapling v2多接受非CA链证书作为颁发者
CVE-2026-93304 6.3 MEDIUM (D)TLS 1.2 客户端接受早期 ChangeCipherSpec 漏洞
CVE-2026-89133 6.3 MEDIUM 中间CA未强制执行NameConstraints策略
CVE-2026-89134 6.3 MEDIUM Subject CN名称约束检查在非DNS SAN存在时被绕过
CVE-2026-89135 6.3 MEDIUM X509_verify_cert失败导致未验证CA保留在共享CertManager
CVE-2026-15442 2.3 LOW 双向(D)TLS关闭期间的堆使用后释放漏洞
CVE-2026-94418 2.3 LOW WOLFSSL 小证书验证下日期错误掩盖签名失败漏洞
CVE-2026-94419 2.3 LOW 客户端会话缓存引用中毒导致与错误服务器恢复连接
CVE-2026-94417 2.3 LOW 启用OCSP且证书无OCSP URL时跳过CRL检查

IV. Related Vulnerabilities

V. Comments for CVE-2026-93302

暂无评论


发表评论