当应用程序在同一个 或证书管理器上同时启用 OCSP 和 CRL 吊销检查时,wolfSSL 会跳过对任何不包含“授权信息访问(Authority Information Access, AIA)OCSP URL”的对等证书的 CRL 检查,并接受那些被已加载的 CRL 列为已吊销的证书。由于缺失响应者时的软失败(soft-fail)策略会将 OCSP 结果在代码判断是否需要 CRL 回退之前先强制视为成功,因此“无响应者存在”与“响应者返回良好状态”变得无法区分。 受影响的是通过 直接启用 OCSP 和 CRL
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93302 | 8.3 HIGH | Trusted peer certificate match ignores public key, allowing forged CA clones |
| CVE-2026-89136 | 8.3 HIGH | Client accepts unsolicited RawPublicKey server certificate type |
| CVE-2026-89102 | 8.3 HIGH | OCSP stapling v2 multi accepts non-CA chain certificates as issuers |
| CVE-2026-93304 | 6.3 MEDIUM | (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange |
| CVE-2026-89133 | 6.3 MEDIUM | NameConstraints not enforced across unconstrained intermediate CA |
| CVE-2026-89134 | 6.3 MEDIUM | Subject CN name-constraint check bypassed when non-DNS SAN present |
| CVE-2026-89135 | 6.3 MEDIUM | Failed X509_verify_cert leaves unverified CA in shared CertManager |
| CVE-2026-15442 | 2.3 LOW | Heap use-after-free on read during bidirectional (D)TLS shutdown |
| CVE-2026-94418 | 2.3 LOW | Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY |
| CVE-2026-94419 | 2.3 LOW | Client session cache reference poisoning allows resumption with wrong server |
No comments yet