Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93302— Trusted peer certificate match ignores public key, allowing forged CA clones

Quick assessment

Affected
wolfSSL wolfSSL
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

函数忽略了所使用的公钥,导致伪造的 CA 克隆可以通过验证。受影响的版本是任何启用 宏,并通过 或 函数加载 CA 证书的版本。攻击者必须知晓哪些证书被加载到上述两个 API 中,才能利用此漏洞。 如果同时定义了 宏,则受影响的功能范围会扩大,涵盖所有 CA 证书的加载操作。在使用自动配置(autoconf)构建时(例如 nginx、haproxy、stunnel、wpas、apache httpd、hitch、bind、rsyslog、ffmpeg、all、distro 等),这两个宏通常都会被定义。 当证书被标

CVSS 8.3 · High EPSS 0.36% · P28

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93302

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Trusted peer certificate match ignores public key, allowing forged CA clones
Source: CVE Program / CVE List V5
Vulnerability Description
MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). The peer must know the certificates being loaded to either of those APIs to take advantage of the issue. When OPENSSL_COMPATIBLE_DEFAULTS is also defined this widens the affected API to include all CA certificate loading. Both macros are defined when using autoconf builds such as (nginx, haproxy, stunnel, wpas, apache httpd, hitch, bind, rsyslog, ffmpeg, all, distro). When the certificate is listed as a trusted peer certificate the issue previously allowed for a malicious (D)TLS server to bypass authentication once knowing which CA’s the client would accept. This also affects mutual authentication cases where the client knows which CA’s the server has loaded. If building with any of these configurations and using (D)TLS where the loaded CA’s could be known and authentication of the peer is desired, users should either: update to the latest wolfSSL version, apply the fix patch, or use the configure flag --disable-openssl-compatible-defaults and not load CA’s with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert() to mitigate the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL wolfSSL 5.3.0 ~ 5.9.2 -

II. Public POCs for CVE-2026-93302

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93302

请登录查看更多情报信息。

Other References for CVE-2026-93302 (1)

Same Patch Batch · wolfSSL · 2026-09-27 · 11 CVEs total

CVE-2026-89136 8.3 HIGH Client accepts unsolicited RawPublicKey server certificate type
CVE-2026-89102 8.3 HIGH OCSP stapling v2 multi accepts non-CA chain certificates as issuers
CVE-2026-93304 6.3 MEDIUM (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
CVE-2026-89133 6.3 MEDIUM NameConstraints not enforced across unconstrained intermediate CA
CVE-2026-89134 6.3 MEDIUM Subject CN name-constraint check bypassed when non-DNS SAN present
CVE-2026-89135 6.3 MEDIUM Failed X509_verify_cert leaves unverified CA in shared CertManager
CVE-2026-15442 2.3 LOW Heap use-after-free on read during bidirectional (D)TLS shutdown
CVE-2026-94418 2.3 LOW Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
CVE-2026-94419 2.3 LOW Client session cache reference poisoning allows resumption with wrong server
CVE-2026-94417 2.3 LOW CRL check skipped when OCSP enabled and certificate has no OCSP URL

IV. Related Vulnerabilities

V. Comments for CVE-2026-93302

No comments yet


Leave a comment